CVE Vulnerabilities

CVE-2017-5137

Insertion of Sensitive Information into Log File

Published: Feb 05, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.2
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Entera_sms_gateway_firmware Sendquick - (including) - (including)

Potential Mitigations

References