{"api_version":"1","generated_at":"2026-07-23T19:44:05+00:00","cve":"CVE-2017-7922","urls":{"html":"https://cve.report/CVE-2017-7922","api":"https://cve.report/api/cve/CVE-2017-7922.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7922","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7922"},"summary":{"title":"CVE-2017-7922","description":"An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes.","state":"PUBLISHED","assigner":"icscert","published_at":"2017-06-21 19:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-269","CWE-269 CWE-269"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.6","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Cambium Networks ePMP | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/99083","name":"http://www.securityfocus.com/bid/99083","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Cambium Networks ePMP ICSA-17-166-01 Privilege Escalation and Access Bypass Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7922","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7922","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Cambium Networks ePMP","version":"affected Cambium Networks ePMP","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7922","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cambium_networks","cpe5":"epmp_1000","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7922","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cambium_networks","cpe5":"epmp_1000_firmware","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7922","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cambium_networks","cpe5":"epmp_1000_hotspot","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7922","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cambium_networks","cpe5":"epmp_1000_hotspot_firmware","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7922","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cambium_networks","cpe5":"epmp_2000","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7922","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cambium_networks","cpe5":"epmp_2000_firmware","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7922","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cambium_networks","cpe5":"epmp_elevate","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7922","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cambium_networks","cpe5":"epmp_elevate_firmware","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T16:19:29.327Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"99083","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/99083"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Cambium Networks ePMP","vendor":"n/a","versions":[{"status":"affected","version":"Cambium Networks ePMP"}]}],"datePublic":"2017-06-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-269","description":"CWE-269","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-06-22T09:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"name":"99083","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/99083"},{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-7922","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Cambium Networks ePMP","version":{"version_data":[{"version_value":"Cambium Networks ePMP"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-269"}]}]},"references":{"reference_data":[{"name":"99083","refsource":"BID","url":"http://www.securityfocus.com/bid/99083"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2017-7922","datePublished":"2017-06-21T19:00:00.000Z","dateReserved":"2017-04-18T00:00:00.000Z","dateUpdated":"2024-08-05T16:19:29.327Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-06-21 19:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-269","CWE-269 CWE-269"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cambium_networks:epmp_1000_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"0F8AFE87-7DE5-4D09-AC45-DDD967939A37"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cambium_networks:epmp_1000:-:*:*:*:*:*:*:*","matchCriteriaId":"A64386E5-D470-4D75-8DBC-1686285BE06F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cambium_networks:epmp_elevate_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"E1A9AA7F-3427-412B-A3D1-0F48E5FD3394"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cambium_networks:epmp_elevate:-:*:*:*:*:*:*:*","matchCriteriaId":"44737752-57D7-4DB3-B9F4-D7E52189F511"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cambium_networks:epmp_2000_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"8B140BE5-6FD1-4588-839E-461658EC851D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cambium_networks:epmp_2000:-:*:*:*:*:*:*:*","matchCriteriaId":"51C390E5-C5B7-449A-AFA1-8C746F08D7C6"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cambium_networks:epmp_1000_hotspot_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"462EBA74-3C0D-427D-8993-BAC5383D8AF9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cambium_networks:epmp_1000_hotspot:-:*:*:*:*:*:*:*","matchCriteriaId":"AC142E94-06B3-4C18-A281-042B66AAB51E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7922","Ordinal":"1","Title":"CVE-2017-7922","CVE":"CVE-2017-7922","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7922","Ordinal":"1","NoteData":"An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes.","Type":"Description","Title":"CVE-2017-7922"},{"CveYear":"2017","CveId":"7922","Ordinal":"2","NoteData":"2017-06-21","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7922","Ordinal":"3","NoteData":"2017-06-22","Type":"Other","Title":"Modified"}]}}}