8
CVSSv3

CVE-2018-10990

Published: 14/05/2018 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 8.5 | Exploitability Score: 6.8
CVSS v3 Base Score: 8 | Impact Score: 6 | Exploitability Score: 1.3
VMScore: 668
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:C

Vulnerability Summary

On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state on the device related to the validity of the "credential" cookie, which might make it easier for malicious users to obtain access at a later time (e.g., "at least for a few minutes"). NOTE: there is no documentation stating that the web UI's logout feature was supposed to do anything beyond removing the cookie from one instance of a web browser; a client-side logout action is often not intended to address cases where a person has made a copy of a cookie outside of a browser.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

commscope arris tg1682g firmware 9.1.103j6