CVE-2022-36307 describes a vulnerability in Airspan AirVelocity 1500 devices where SNMP credentials are inadvertently printed to the physically accessible serial port during boot, potentially affecting other AirVelocity and AirSpeed models. This medium-severity vulnerability (CVSS 6.8) requires physical access to the device (AV:P) but allows for full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) without user interaction. While the vulnerability has a low EPSS score and no known public exploits or active exploitation, it poses a significant risk if an attacker gains physical access. A fix is available in AirVelocity 1500 software version 15.18.00.2511.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.3.0.01249, <= 15.18.00.2511CPE matchmatch criteria | cpe:2.3:o:airspan:airvelocity_1500_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.