CVE Vulnerabilities

CVE-2017-5254

Improper Privilege Management

Published: Dec 20, 2017 | Modified: Oct 09, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users installer and home have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Epmp_1000_firmware Cambiumnetworks * 3.5 (including)

Potential Mitigations

References