Information disclosure in VGo Celia - CVE-2018-8860

 

Information disclosure in VGo Celia - CVE-2018-8860

Published: April 25, 2018 / Updated: October 19, 2018


Vulnerability identifier: #VU12167
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-8860
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: Vecna Technologies
Affected software:
VGo Celia

Detailed vulnerability description

The vulnerability allows an adjacent attacker to obtain potentially sensitive information on the target system.

The weakness exists due to cleartext transmission of sensitive information. An adjacent attacker can capture firmware updates through the adjacent network.

How to mitigate CVE-2018-8860

Update to version 3.0.3.53662.

Sources