Show plain JSON{"id": "CVE-2022-36307", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.8, "attackVector": "PHYSICAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 0.9}]}, "published": "2022-08-16T01:15:13.310", "references": [{"url": "https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-8j75-qh6c-wpc5", "tags": ["Third Party Advisory"], "source": "cve-assign@fb.com"}, {"url": "https://helpdesk.airspan.com/browse/TRN3-1693", "tags": ["Permissions Required", "Vendor Advisory"], "source": "cve-assign@fb.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-522"}]}, {"type": "Secondary", "source": "cve-assign@fb.com", "description": [{"lang": "en", "value": "CWE-522"}]}], "descriptions": [{"lang": "en", "value": "The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models."}, {"lang": "es", "value": "AirVelocity 1500 imprime las credenciales SNMP en su puerto serie f\u00edsicamente accesible durante el arranque. Esto fue corregido en versi\u00f3n 15.18.00.2511 del software de AirVelocity 1500 y puede afectar a otros modelos de AirVelocity y AirSpeed."}], "lastModified": "2022-08-17T14:11:35.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:airspan:airvelocity_1500:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DB5DBFEA-0C64-4E87-A11E-6C850D4C87CE"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:airspan:airvelocity_1500_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ECF71DBB-8D4C-4A82-8F4B-3907062C1379", "versionEndIncluding": "15.18.00.2511", "versionStartIncluding": "9.3.0.01249"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve-assign@fb.com"}