PT-2015-6358 · Belden Garrettcom · Magnum 6K+1

Ashish Kamble

+1

·

Publicado

2015-08-04

·

Atualizado

2016-12-06

·

CVE-2015-3959

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Belden GarrettCom Magnum 6K and Magnum 10K switches firmware versions prior to 4.5.6
Description The issue concerns a hardcoded serial-console password for a privileged account in the firmware of the affected switches. This might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation where this account is enabled, and leveraging knowledge of this password.
Recommendations For firmware versions prior to 4.5.6, update to version 4.5.6 or later to resolve the issue. As a temporary workaround, consider disabling the privileged account with the hardcoded serial-console password until a patch is available. Restrict physical access to the switches to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2015-3959

Produtos afetados

Magnum 10K
Magnum 6K