peter bassill · operator
$ cve CVE-2018-11542 JSON

CVE-2018-11542

9.8
CRITICAL · CVSS 3.0 · EPSS 3.4% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A Remote Command Execution (RCE) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the execution of arbitrary commands via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to Build 485. It affects the SWe Lite devices 6.1.x up to Build 111 and 7.0.x up to Build 140.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.44% — more likely to be exploited than 89% of all CVEs
On CISA KEVno
Public exploitnone known
Published2018-07-09
Last modified2026-06-17

Affected (6)

VendorProduct
ribboncommunicationssbc swe lite
ribboncommunicationssbc swe lite firmware
ribboncommunicationssonus sbc 1000
ribboncommunicationssonus sbc 1000 firmware
ribboncommunicationssonus sbc 2000
ribboncommunicationssonus sbc 2000 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD