CVE-2018-20387

CRITICAL

Bnmux Bcw700j Firmware - Insufficiently Protected Credentials

Title source: rule

Description

Bnmux BCW700J 5.20.7, BCW710J 5.30.6a, and BCW710J2 5.30.16 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

Scores

CVSS v3 9.8
EPSS 0.0064
EPSS Percentile 70.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522
Status published

Affected Products (3)

bnmux/bcw700j_firmware
bnmux/bcw710j_firmware
bnmux/bcw710j2_firmware

Timeline

Published Dec 23, 2018
Tracked Since Feb 18, 2026