CVE-2018-8880

Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network information disclosure.
References
Link Resource
https://www.exploit-db.com/exploits/44488/ Exploit Third Party Advisory
http://sadfud.me/explotos/deviceip.txt Exploit Third Party Advisory
Configurations

Configuration 1


Information

Published : 2018-04-23 06:29

Updated : 2018-05-25 03:39


NVD link : CVE-2018-8880

Mitre link : CVE-2018-8880

Products Affected
No products.
CWE