CVE-2018-20387

CRITICAL

Bnmux BCW700J 5.20.7 BCW710J 5.30.6a BCW710J2 5.30.16 - Unauthenticated Credential Exposure via SNMP OID Requests

Title source: llm
STIX 2.1

Description

Bnmux BCW700J 5.20.7, BCW710J 5.30.6a, and BCW710J2 5.30.16 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

Scores

CVSS v3 9.8
EPSS 0.0151
EPSS Percentile 71.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (3)
bnmux/bcw700j_firmware 5.20.7
bnmux/bcw710j2_firmware 5.30.16
bnmux/bcw710j_firmware 5.30.6a
Published Dec 23, 2018
Tracked Since Feb 18, 2026