VDB
CVE-2018-5402
CVE-2018-5402
PUBLISHED
CVSS 9.1 CRITICAL
Reported by certcc · Published October 8, 2018
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PIN Impact: An attacker once authenticated can change configurations, upload new configuration files, and upload executable code via file upload for firmware updates. Requires access to the network. Affected releases are Auto-Maskin DCU-210E, RP-210E, and the Marine Pro Observer Android App. Versions prior to 3.7 on ARMv7.
Risk Scores
CVSS 3.0
9.1
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Auto-Maskin | DCU-210E | 3.7 |
| Auto-Maskin | RP-210E | 3.7 |
| Auto-Maskin | DCU-210E | 3.7 |
| Auto-Maskin | RP-210E | 3.7 |
Timeline
- Oct 6, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- VU#176301 third-party-advisoryx_refsource_CERT-VN
- x_refsource_MISC