CVE-2018-20393

Summary

CVECVE-2018-20393
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2018-12-23 21:29:00 UTC
Updated2020-08-24 17:37:00 UTC
DescriptionTechnicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU, CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC, DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a, TC7110.AR STD3.38.03, TC7110.B STC8.62.02, TC7110.D STDB.79.02, TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT, and TC7200.TH2v2 SC05.00.22 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

Risk And Classification

Problem Types: NVD-CWE-noinfo

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Technicolor Cga0101 1.0 All All All
Hardware Technicolor Cga0101 1.0 All All All
Operating System Technicolor Cga0101 Firmware cwa0101e-a23e-c7000r5712-170315-skc All All All
Operating System Technicolor Cga0101 Firmware cwa0101e-a23e-c7000r5712-170315-skc All All All
Hardware Technicolor Cga0111 1.0 All All All
Hardware Technicolor Cga0111 1.0 All All All
Operating System Technicolor Cga0111 Firmware cga0111e-es-13-e23e-c8000r5712-170217-0829-tru All All All
Operating System Technicolor Cga0111 Firmware cga0111e-es-13-e23e-c8000r5712-170217-0829-tru All All All
Hardware Technicolor Dpc3928sl 1.0 All All All
Hardware Technicolor Dpc3928sl 1.0 All All All
Operating System Technicolor Dpc3928sl Firmware d3928sl-psip-13-a010-c3420r55105-170214a All All All
Operating System Technicolor Dpc3928sl Firmware d3928sl-psip-13-a010-c3420r55105-170214a All All All
Hardware Technicolor Tc7110.ar 1.0 All All All
Hardware Technicolor Tc7110.ar 1.0 All All All
Operating System Technicolor Tc7110.ar Firmware std3.38.03 All All All
Operating System Technicolor Tc7110.ar Firmware std3.38.03 All All All
Hardware Technicolor Tc7110.b 2.0 All All All
Hardware Technicolor Tc7110.b 2.0 All All All
Operating System Technicolor Tc7110.b Firmware stc8.62.02 All All All
Operating System Technicolor Tc7110.b Firmware stc8.62.02 All All All
Hardware Technicolor Tc7110.d 1.0 All All All
Hardware Technicolor Tc7110.d 1.0 All All All
Operating System Technicolor Tc7110.d Firmware stdb.79.02 All All All
Operating System Technicolor Tc7110.d Firmware stdb.79.02 All All All
Hardware Technicolor Tc7200.d1i 1.0 All All All
Hardware Technicolor Tc7200.d1i 1.0 All All All
Operating System Technicolor Tc7200.d1i Firmware tc7200.d1ie-n23e-c7000r5712-170406-hat All All All
Operating System Technicolor Tc7200.d1i Firmware tc7200.d1ie-n23e-c7000r5712-170406-hat All All All
Hardware Technicolor Tc7200.th2v2.d1i 01.00 All All All
Hardware Technicolor Tc7200.th2v2.d1i 01.00 All All All
Operating System Technicolor Tc7200.th2v2.d1i Firmware sc05.00.22 All All All
Operating System Technicolor Tc7200.th2v2.d1i Firmware sc05.00.22 All All All

References

ReferenceSourceLinkTags
Capitan Alfa: [stringbleed] y ahora que ? ...Passwords Leaks ( CVE-2018-203580 a CVE-2018-20401) MISC misteralfa-hack.blogspot.com Exploit, Third Party Advisory
sensitivesOids/oidpassswordleaks.csv at master · ezelf/sensitivesOids · GitHub MISC github.com Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report