CVE-2018-16591
Summary
| CVE | CVE-2018-16591 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-10 17:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Furuno | Felcom 250 | - | All | All | All |
| Hardware | Furuno | Felcom 250 | - | All | All | All |
| Operating System | Furuno | Felcom 250 Firmware | - | All | All | All |
| Operating System | Furuno | Felcom 250 Firmware | - | All | All | All |
| Hardware | Furuno | Felcom 500 | - | All | All | All |
| Hardware | Furuno | Felcom 500 | - | All | All | All |
| Operating System | Furuno | Felcom 500 Firmware | - | All | All | All |
| Operating System | Furuno | Felcom 500 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2018-16591 - The Furuno Felcom250 and Felcom500 devices allowed unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SIM" panel. · GitHub | MISC | gist.github.com | Third Party Advisory |
| CyberSKR - Cyber Security Consultancy | MISC | cyberskr.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.