Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:watchguard:ap200_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "263A0D62-FCC4-4374-8E2F-1393140D68B0", "versionEndExcluding": "1.2.9.15", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:watchguard:ap200:-:*:*:*:*:*:*:*", "matchCriteriaId": "5C6FA1D0-016C-4B73-9BC4-83848A1A6D04", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:watchguard:ap102_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "FA60491C-1B5B-4E23-B27D-4285E3F71E99", "versionEndExcluding": "1.2.9.15", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:watchguard:ap102:-:*:*:*:*:*:*:*", "matchCriteriaId": "6E009741-C76C-49F3-83A4-4BB17D1A9510", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:watchguard:ap100_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "428B2A59-5F74-4685-B6A9-F0CC9AFEE949", "versionEndExcluding": "1.2.9.15", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:watchguard:ap100:-:*:*:*:*:*:*:*", "matchCriteriaId": "8379C407-E7DC-4193-9BD0-5BAE24E637B8", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:watchguard:ap300_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "3B830CD7-1683-4C41-9B61-5ED8237EA46C", "versionEndExcluding": "2.0.0.10", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:watchguard:ap300:-:*:*:*:*:*:*:*", "matchCriteriaId": "473F5A2F-00B4-4D6E-9E4F-F81B7018DA60", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}], "descriptions": [{"lang": "en", "value": "An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root."}, {"lang": "es", "value": "Se ha descubierto un problema en los dispositivos WatchGuard AP100, AP102 y AP200 con firmware en versiones anteriores a la 1.2.9.15 y en los dispositivos AP300 con firmware en versiones anteriores a la 2.0.0.10. La funcionalidad de subida de archivos permite que cualquier usuario autenticado en la interfaz web suba archivos que contienen c\u00f3digo al root web, lo que permite que estos archivos se ejecuten como root."}], "id": "CVE-2018-10577", "lastModified": "2024-11-21T03:41:35.817", "metrics": {"cvssMetricV2": [{"acInsufInfo": true, "baseSeverity": "HIGH", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "COMPLETE", "baseScore": 9.0, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C", "version": "2.0"}, "exploitabilityScore": 8.0, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV30": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0"}, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2018-05-02T21:29:00.980", "references": [{"source": "cve@mitre.org", "tags": ["Mailing List", "Third Party Advisory"], "url": "http://seclists.org/fulldisclosure/2018/May/12"}, {"source": "cve@mitre.org", "url": "https://www.exploit-db.com/exploits/45409/"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mailing List", "Third Party Advisory"], "url": "http://seclists.org/fulldisclosure/2018/May/12"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.exploit-db.com/exploits/45409/"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-434"}], "source": "nvd@nist.gov", "type": "Primary"}]}