Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-10577


An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.


Published

2018-05-02T21:29:00.980

Last Modified

2024-11-21T03:41:35.817

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System watchguard ap200_firmware < 1.2.9.15 Yes
Hardware watchguard ap200 - No
Operating System watchguard ap102_firmware < 1.2.9.15 Yes
Hardware watchguard ap102 - No
Operating System watchguard ap100_firmware < 1.2.9.15 Yes
Hardware watchguard ap100 - No
Operating System watchguard ap300_firmware < 2.0.0.10 Yes
Hardware watchguard ap300 - No

References