CVE-2018-17935

All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.
References
Link Resource
http://www.securityfocus.com/bid/105732 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-296-03 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:telecrane:f25-2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-2s:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:telecrane:f25-2d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-2d:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:telecrane:f25-4s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-4s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:telecrane:f25-4d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-4d:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:telecrane:f25-6s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-6s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:telecrane:f25-6d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-6d:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:telecrane:f25-8s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-8s:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:telecrane:f25-8d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-8d:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:telecrane:f25-10s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-10s:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:telecrane:f25-10d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-10d:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:telecrane:f25-60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:telecrane:f25-60:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-10-24 13:29

Updated : 2024-02-28 16:48


NVD link : CVE-2018-17935

Mitre link : CVE-2018-17935

CVE.ORG link : CVE-2018-17935


JSON object : View

Products Affected

telecrane

  • f25-6s_firmware
  • f25-8s_firmware
  • f25-6d_firmware
  • f25-4d
  • f25-6s
  • f25-8d
  • f25-4s
  • f25-4s_firmware
  • f25-2s
  • f25-10s
  • f25-60
  • f25-10s_firmware
  • f25-2d
  • f25-10d_firmware
  • f25-6d
  • f25-2s_firmware
  • f25-10d
  • f25-4d_firmware
  • f25-8s
  • f25-8d_firmware
  • f25-2d_firmware
  • f25-60_firmware
CWE
CWE-294

Authentication Bypass by Capture-replay