PT-2013-2123 · Digital Alert Systems+1 · Dasdec+1
Cesar Cerrudo
+1
·
Publicado
2013-06-29
·
Atualizado
2020-01-29
·
CVE-2013-0137
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Digital Alert Systems DASDEC EAS device versions prior to 2.0-2
Monroe Electronics R189 One-Net EAS device versions prior to 2.0-2
Description
The default configuration of the affected devices contains a known SSH private key, allowing remote attackers to obtain root access and spoof alerts via an SSH session.
Recommendations
For Digital Alert Systems DASDEC EAS device versions prior to 2.0-2, update to version 2.0-2 or later to resolve the issue.
For Monroe Electronics R189 One-Net EAS device versions prior to 2.0-2, update to version 2.0-2 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dasdec
R189 One-Net