Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Dirk Wetter

#26594de 53,638
9.6CVSS total
Vulnerabilidades · 2
Média
2
PT-2005-3821
4.6
2005-09-19
Avocent · Avocent Ccm Console Server · CVE-2005-2984
**Name of the Vulnerable Software and Affected Versions** Avocent CCM console server version 2.1 CCM4850 **Description** The issue allows remote authenticated attackers to bypass port restrictions. This can be achieved by connecting to the server via SSH and using the `connect` command to access the serial port. **Recommendations** For Avocent CCM console server version 2.1 CCM4850, consider restricting access to the SSH connection and limiting the use of the `connect` command to authorized personnel only. As a temporary workaround, restrict access to the serial port until a patch is available.
PT-2005-3118
5.0
2005-07-10
Lantronix · Secure Linux · CVE-2005-2189
Name of the Vulnerable Software and Affected Versions: Lantronix SecureLinx console server versions 2.0 through 3.0 Description: The issue allows remote attackers to obtain sensitive information, such as SSH private keys, due to insufficient access control of the /etc/ssh directory stored under the web document root. Recommendations: For versions 2.0 through 3.0, restrict access to the /etc/ssh directory to minimize the risk of exploitation. Consider reconfiguring the web document root to exclude sensitive directories.