ID

VAR-201707-1349


TITLE

SNMP Protocol Community String Authentication Bypass Vulnerability in Lenovo NetPower V Firewall

Trust: 0.6

sources: CNVD: CNVD-2017-07102

DESCRIPTION

Lenovo PowerV Firewall is a comprehensive UTM that integrates firewall, IPSec VPN, SSL VPN, intrusion detection and protection system, antivirus, vulnerability scanning, active defense, flow control, log audit, and centralized management. Lenovo NetPower V firewall has SNMP protocol community string authentication permission bypass vulnerability, allowing attackers to use arbitrary strings or integer values to bypass SNMP access control and write arbitrary strings in MIB (Management Information Base) To get sensitive information about the device.

Trust: 0.6

sources: CNVD: CNVD-2017-07102

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-07102

AFFECTED PRODUCTS

vendor:wangyu nebula informationmodel:power firewallscope:eqversion:v

Trust: 0.6

sources: CNVD: CNVD-2017-07102

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-07102
value: HIGH

Trust: 0.6

CNVD: CNVD-2017-07102
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-07102

PATCH

title:SNMP Protocol Community String Authentication Bypass Vulnerability in Lenovo NetPower V Firewallurl:https://www.cnvd.org.cn/patchinfo/show/93987

Trust: 0.6

sources: CNVD: CNVD-2017-07102

EXTERNAL IDS

db:CNVDid:CNVD-2017-07102

Trust: 0.6

sources: CNVD: CNVD-2017-07102

SOURCES

db:CNVDid:CNVD-2017-07102

LAST UPDATE DATE

2022-05-04T09:39:29.149000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-07102date:2017-05-26T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-07102date:2017-07-04T00:00:00