Security readout for executives and security teams
Plain-English summary
Some ARRIS DG950A and DG950S cable gateway firmware versions can expose stored credentials through SNMP queries. If SNMP is reachable from untrusted networks, an attacker may be able to obtain credentials without needing device access. The sources do not identify a vendor patch or confirm active exploitation.
Executive priority
Prioritize finding exposed affected devices because the issue involves credential disclosure. Treat internet-reachable or broadly reachable SNMP as urgent. If devices are isolated to trusted management networks, handle through normal vulnerability remediation with credential rotation.
Technical view
CVE-2018-20383 describes credential disclosure on ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO via specific SNMP OID requests. The record provides no CVSS score, CWE, vendor advisory, or patch details. KEV status is false in the supplied bundle.
Likely exposure
Exposure is most likely where affected ARRIS DG950A or DG950S devices run the named firmware and SNMP is enabled or reachable from untrusted networks. Internal-only management networks reduce risk but do not remove it.
Exploitation context
The source says remote attackers can discover credentials through SNMP requests. The supplied data does not show CISA KEV listing, active exploitation, public exploit tooling, authentication requirements, or attack prevalence.
Researcher notes
The public record is sparse: no CVSS vector, affected CPEs, CWE, vendor fix, or exploitation evidence are provided. Analysis relies on the CVE description and linked references naming sensitive SNMP OID credential leakage.
Mitigation direction
- Identify any ARRIS DG950A 7.10.145 or DG950S 7.10.145.EURO devices.
- Disable SNMP if it is not operationally required.
- Restrict SNMP to trusted management hosts and networks only.
- Rotate credentials exposed or stored on affected devices.
- Check ARRIS or service-provider guidance for firmware updates or replacement options.
Validation and detection
- Inventory gateway model and firmware from asset records or management interfaces.
- Confirm whether SNMP is enabled and where it is reachable from.
- Review firewall and ACL rules protecting device management services.
- Check logs for unexpected SNMP access from untrusted sources.
- Validate sensitive OID exposure only in an authorized controlled environment.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-20383 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/ezelf/sensitivesOids/blob/master/oidpassswordleaks.csvCVE reference · x_refsource_MISC
- https://misteralfa-hack.blogspot.com/2018/12/stringbleed-y-ahora-que-passwords-leaks.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
