CVE-2018-20383

CRITICAL

ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO - Unauthenticated Credential Exposure via SNMP OID Requests

Title source: llm
STIX 2.1

Description

ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

Scores

CVSS v3 9.8
EPSS 0.0182
EPSS Percentile 76.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (2)
arris/dg950s_firmware 7.10.145.euro
commscope/arris_dg950a_firmware 7.10.145
Published Dec 23, 2018
Tracked Since Feb 18, 2026