CVE-2018-20399

CRITICAL

Motorola SBG901 SBG941 and SVG1202 Firmware - Unauthenticated Credential Exposure via SNMP OID Requests

Title source: llm
STIX 2.1

Description

Motorola SBG901 SBG901-2.10.1.1-GA-00-581-NOSH, SBG941 SBG941-2.11.0.0-GA-07-624-NOSH, and SVG1202 SVG1202-2.1.0.0-GA-14-LTSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106320

Scores

CVSS v3 9.8
EPSS 0.0259
EPSS Percentile 83.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (3)
motorola/sbg901_firmware sbg901-2.10.1.1-ga-00-581-nosh
motorola/sbg941_firmware sbg941-2.11.0.0-ga-07-624-nosh
motorola/svg1202_firmware svg1202-2.1.0.0-ga-14-ltsh
Published Dec 23, 2018
Tracked Since Feb 18, 2026