CVE-2017-7918 is an Improper Access Control vulnerability affecting Cambium Networks ePMP devices, including various ePMP 1000, 2000, and Elevate firmware versions. An authenticated attacker can remotely trigger device configuration backups via specific SNMP MIBs after a valid user has performed an SNMP configuration export. This leads to high confidentiality and low integrity/availability impacts due to sensitive information exposure and potential configuration changes. Rated Medium severity (CVSS 6.8), the vulnerability requires low privileges and no user interaction, but has a network attack vector. While not actively exploited in the wild and not on the KEV catalog, a Metasploit auxiliary module exists for SNMP enumeration, indicating exploitability. Despite its FAUCET Risk Score of 97/100, there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cambium_networks:epmp_1000_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cambium_networks:epmp_elevate_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cambium_networks:epmp_2000_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cambium_networks:epmp_1000_hotspot_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.