Vulnerability Details CVE-2018-10285
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.488
EPSS Ranking 97.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-10285
-
cpe:2.3:a:ericssonlg:ipecs_nms:a.1ac