VYPR
High severity8.8NVD Advisory· Published Mar 27, 2019· Updated Jun 17, 2026

CVE-2018-19648

CVE-2018-19648

Description

An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged users to create privileged users and execute arbitrary commands via the use of the diagnostic-profile over RESTCONF.

Affected products

3
  • Adtran/PMAA3 versions
    cpe:2.3:a:adtran:pmaa:1.6.2:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:adtran:pmaa:1.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:adtran:pmaa:1.6.3:*:*:*:*:*:*:*
    • (no CPE)range: 1.6.2-1, 1.6.3, and 1.6.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.