VDB

CVE-2018-5402

CVE-2018-5402 PUBLISHED CVSS 9.1 CRITICAL

Reported by certcc · Published October 8, 2018

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PIN Impact: An attacker once authenticated can change configurations, upload new configuration files, and upload executable code via file upload for firmware updates. Requires access to the network. Affected releases are Auto-Maskin DCU-210E, RP-210E, and the Marine Pro Observer Android App. Versions prior to 3.7 on ARMv7.

Risk Scores

CVSS 3.0
9.1
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Auto-MaskinDCU-210E3.7
Auto-MaskinRP-210E3.7
Auto-MaskinDCU-210E3.7
Auto-MaskinRP-210E3.7

Timeline

  • Oct 6, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score

References

  • VU#176301 third-party-advisoryx_refsource_CERT-VN
  • x_refsource_MISC
Open in Interactive Console →
$ Console Community · 100/wk Open console ›