CVE-2018-19648

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
27/03/2019
Last modified:
03/10/2019

Description

An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged users to create privileged users and execute arbitrary commands via the use of the diagnostic-profile over RESTCONF.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adtran:pmaa:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:adtran:pmaa:1.6.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools