The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
References
Link | Resource |
---|---|
https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-8j75-qh6c-wpc5 | Third Party Advisory |
https://helpdesk.airspan.com/browse/TRN3-1693 | Permissions Required Vendor Advisory |
https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-8j75-qh6c-wpc5 | Third Party Advisory |
https://helpdesk.airspan.com/browse/TRN3-1693 | Permissions Required Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 07:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-8j75-qh6c-wpc5 - Third Party Advisory | |
References | () https://helpdesk.airspan.com/browse/TRN3-1693 - Permissions Required, Vendor Advisory |
Information
Published : 2022-08-16 01:15
Updated : 2024-11-21 07:12
NVD link : CVE-2022-36307
Mitre link : CVE-2022-36307
CVE.ORG link : CVE-2022-36307
JSON object : View
Products Affected
airspan
- airvelocity_1500
- airvelocity_1500_firmware
CWE
CWE-522
Insufficiently Protected Credentials