CVE-2018-8859

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
24/07/2018
Last modified:
09/10/2019

Description

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:echelon:smartserver_1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:echelon:smartserver_1:-:*:*:*:*:*:*:*
cpe:2.3:o:echelon:smartserver_2_firmware:*:*:*:*:*:*:*:* 4.11.007 (excluding)
cpe:2.3:h:echelon:smartserver_2:-:*:*:*:*:*:*:*
cpe:2.3:o:echelon:i.lon_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:echelon:i.lon_100:-:*:*:*:*:*:*:*
cpe:2.3:o:echelon:i.lon_600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:echelon:i.lon_600:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools