ID

VAR-201704-1230


CVE

CVE-2017-8076


TITLE

TP-Link TL-SG108E Vulnerabilities related to cryptographic strength

Trust: 0.8

sources: JVNDB: JVNDB-2017-003275

DESCRIPTION

On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.50749 firmware. TP-Link TL-SG108E Contains a cryptographic strength vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) An attack may be carried out. The TP-LinkTL-SG108E is a Gigabit Ethernet switch. A security vulnerability exists in the TP-LinkTL-SG108E1.0 version using firmware version 1.1.2Build20141017Rel.50749. An attacker could exploit the vulnerability to obtain information

Trust: 2.34

sources: NVD: CVE-2017-8076 // JVNDB: JVNDB-2017-003275 // CNVD: CNVD-2017-06638 // VULHUB: VHN-116279 // VULMON: CVE-2017-8076

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-06638

AFFECTED PRODUCTS

vendor:tp linkmodel:tl-sg108escope:eqversion:1.1.2

Trust: 1.6

vendor:tp linkmodel:tl-sg108escope:eqversion:1.1.2 build 20141017

Trust: 0.8

vendor:tp linkmodel:tl-sg108e build rel.50749scope:eqversion:1.1.220141017

Trust: 0.6

sources: CNVD: CNVD-2017-06638 // JVNDB: JVNDB-2017-003275 // CNNVD: CNNVD-201704-1120 // NVD: CVE-2017-8076

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-8076
value: CRITICAL

Trust: 1.0

NVD: CVE-2017-8076
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2017-06638
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201704-1120
value: HIGH

Trust: 0.6

VULHUB: VHN-116279
value: HIGH

Trust: 0.1

VULMON: CVE-2017-8076
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-8076
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2017-06638
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-116279
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-8076
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-06638 // VULHUB: VHN-116279 // VULMON: CVE-2017-8076 // JVNDB: JVNDB-2017-003275 // CNNVD: CNNVD-201704-1120 // NVD: CVE-2017-8076

PROBLEMTYPE DATA

problemtype:CWE-326

Trust: 1.9

sources: VULHUB: VHN-116279 // JVNDB: JVNDB-2017-003275 // NVD: CVE-2017-8076

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201704-1120

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201704-1120

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-003275

PATCH

title:TL-SG108Eurl:http://www.tp-link.in/products/details/cat-41_TL-SG108E.html

Trust: 0.8

title:Patch for TP-LinkTL-SG108ERC4 encoding vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/93718

Trust: 0.6

title: - url:https://github.com/geeklynad/TP-Link-ESCU

Trust: 0.1

sources: CNVD: CNVD-2017-06638 // VULMON: CVE-2017-8076 // JVNDB: JVNDB-2017-003275

EXTERNAL IDS

db:NVDid:CVE-2017-8076

Trust: 3.2

db:JVNDBid:JVNDB-2017-003275

Trust: 0.8

db:CNNVDid:CNNVD-201704-1120

Trust: 0.7

db:CNVDid:CNVD-2017-06638

Trust: 0.6

db:VULHUBid:VHN-116279

Trust: 0.1

db:VULMONid:CVE-2017-8076

Trust: 0.1

sources: CNVD: CNVD-2017-06638 // VULHUB: VHN-116279 // VULMON: CVE-2017-8076 // JVNDB: JVNDB-2017-003275 // CNNVD: CNNVD-201704-1120 // NVD: CVE-2017-8076

REFERENCES

url:https://chmod750.com/2017/04/23/vulnerability-disclosure-tp-link/

Trust: 3.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-8076

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-8076

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/326.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://github.com/geeklynad/tp-link-escu

Trust: 0.1

sources: CNVD: CNVD-2017-06638 // VULHUB: VHN-116279 // VULMON: CVE-2017-8076 // JVNDB: JVNDB-2017-003275 // CNNVD: CNNVD-201704-1120 // NVD: CVE-2017-8076

SOURCES

db:CNVDid:CNVD-2017-06638
db:VULHUBid:VHN-116279
db:VULMONid:CVE-2017-8076
db:JVNDBid:JVNDB-2017-003275
db:CNNVDid:CNNVD-201704-1120
db:NVDid:CVE-2017-8076

LAST UPDATE DATE

2025-04-20T23:34:27.188000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-06638date:2017-05-21T00:00:00
db:VULHUBid:VHN-116279date:2017-04-27T00:00:00
db:VULMONid:CVE-2017-8076date:2017-04-27T00:00:00
db:JVNDBid:JVNDB-2017-003275date:2017-05-24T00:00:00
db:CNNVDid:CNNVD-201704-1120date:2017-05-10T00:00:00
db:NVDid:CVE-2017-8076date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-06638date:2017-05-16T00:00:00
db:VULHUBid:VHN-116279date:2017-04-23T00:00:00
db:VULMONid:CVE-2017-8076date:2017-04-23T00:00:00
db:JVNDBid:JVNDB-2017-003275date:2017-05-24T00:00:00
db:CNNVDid:CNNVD-201704-1120date:2017-04-23T00:00:00
db:NVDid:CVE-2017-8076date:2017-04-23T16:59:00.220