Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-10890


Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmware versions prior to 91.09.17.10 allows an attacker on the same LAN to perform arbitrary operations or access information via unspecified vectors.


Published

2017-11-17T14:29:00.403

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 4.6 (MEDIUM)

CVSSv2 Vector

AV:A/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

5.5

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-384

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System sharp rx-v200_firmware < 09.87.17.09 Yes
Hardware sharp rx-v200 - No
Operating System sharp rx-v100_firmware < 03.29.17.09 Yes
Hardware sharp rx-v100 - No
Operating System sharp rx-clv1-p_firmware < 79.17.17.09 Yes
Hardware sharp rx-clv1-p - No
Operating System sharp rx-clv2-b_firmware < 89.07.17.09 Yes
Hardware sharp rx-clv2-b - No
Operating System sharp rx-clv3-n_firmware < 91.09.17.10 Yes
Hardware sharp rx-clv3-n - No

References