CVE-2018-18877
HIGHColumbia Weather MicroServer MS_2.6.9900 Authenticated Bypass via Alt Config
Title source: llmDescription
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://applied-risk.com/labs/advisories
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-19-078-02
Scores
CVSS v3
8.8
EPSS
0.0171
EPSS Percentile
74.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (1)
columbiaweather/weather_microserver_firmware
ms_2.6.9900
Published
Jun 18, 2019
Tracked Since
Feb 18, 2026