CVE-2018-17935
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/10/2018
Last modified:
18/09/2020
Description
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
4.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:telecrane:f25-2s_firmware:*:*:*:*:*:*:*:* | 00.0a (excluding) | |
| cpe:2.3:h:telecrane:f25-2s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:telecrane:f25-2d_firmware:*:*:*:*:*:*:*:* | 00.0a (excluding) | |
| cpe:2.3:h:telecrane:f25-2d:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:telecrane:f25-4s_firmware:*:*:*:*:*:*:*:* | 00.0a (excluding) | |
| cpe:2.3:h:telecrane:f25-4s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:telecrane:f25-4d_firmware:*:*:*:*:*:*:*:* | 00.0a (excluding) | |
| cpe:2.3:h:telecrane:f25-4d:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:telecrane:f25-6s_firmware:*:*:*:*:*:*:*:* | 00.0a (excluding) | |
| cpe:2.3:h:telecrane:f25-6s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:telecrane:f25-6d_firmware:*:*:*:*:*:*:*:* | 00.0a (excluding) | |
| cpe:2.3:h:telecrane:f25-6d:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:telecrane:f25-8s_firmware:*:*:*:*:*:*:*:* | 00.0a (excluding) | |
| cpe:2.3:h:telecrane:f25-8s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:telecrane:f25-8d_firmware:*:*:*:*:*:*:*:* | 00.0a (excluding) |
To consult the complete list of CPE names with products and versions, see this page



