CVE-2022-36307
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
16/08/2022
Last modified:
17/08/2022
Description
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:airspan:airvelocity_1500_firmware:*:*:*:*:*:*:*:* | 9.3.0.01249 (including) | 15.18.00.2511 (including) |
| cpe:2.3:h:airspan:airvelocity_1500:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



