445
VMScore

CVE-2017-9132

Published: 21/05/2017 Updated: 26/05/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A hard-coded credentials issue exists on Mimosa Client Radios prior to 2.2.3, Mimosa Backhaul Radios prior to 2.2.3, and Mimosa Access Points prior to 2.2.3. These devices run Mosquitto, a lightweight message broker, to send information between devices. By using the vendor's hard-coded credentials to connect to the broker on any device (whether it be an AP, Client, or Backhaul model), an attacker can view all the messages being sent between the devices. If an attacker connects to an AP, the AP will leak information about any clients connected to it, including the serial numbers, which can be used to remotely factory reset the clients via a page in their web interface.

Vulnerable Product Search on Vulmon Subscribe to Product

mimosa client radios

mimosa backhaul radios