Vulnerability Details CVE-2017-7318
Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.101
EPSS Ranking 92.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2017-7318
-
cpe:2.3:h:siklu:etherhaul-5500fd:-
-
cpe:2.3:h:siklu:etherhaul_500tx:-
-
cpe:2.3:h:siklu:etherhaul_60ghz_v-band_radio:-
-
cpe:2.3:h:siklu:etherhaul_70/80ghz_gigabit_radio:-
-
cpe:2.3:h:siklu:etherhaul_70/80ghz_multi-gigabit_e-band_radio:-
-
cpe:2.3:h:siklu:etherhaul_70ghz_e-band_radio:-
-
cpe:2.3:o:siklu:etherhaul_firmware:3.7.0
-
cpe:2.3:o:siklu:etherhaul_firmware:6.0
-
cpe:2.3:o:siklu:etherhaul_firmware:7.3.0