CVE-2018-14529

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
05/07/2019
Last modified:
11/07/2019

Description

Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:invoxia:nvx220_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:invoxia:nvx220:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools