A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user. An attacker can activate snmpd without any configuration changes to trigger this vulnerability.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: talos

Published: 2019-05-06T18:28:04

Updated: 2019-05-07T19:14:51

Reserved: 2018-01-02T00:00:00


Link: CVE-2018-4062

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-05-06T19:29:00.577

Modified: 2019-05-08T17:03:19.923


Link: CVE-2018-4062

JSON object: View

cve-icon Redhat Information

No data.

CWE