PT-2015-6358 · Belden Garrettcom · Magnum 6K+1
Ashish Kamble
+1
·
Publicado
2015-08-04
·
Atualizado
2016-12-06
·
CVE-2015-3959
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Belden GarrettCom Magnum 6K and Magnum 10K switches firmware versions prior to 4.5.6
Description
The issue concerns a hardcoded serial-console password for a privileged account in the firmware of the affected switches. This might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation where this account is enabled, and leveraging knowledge of this password.
Recommendations
For firmware versions prior to 4.5.6, update to version 4.5.6 or later to resolve the issue. As a temporary workaround, consider disabling the privileged account with the hardcoded serial-console password until a patch is available. Restrict physical access to the switches to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Magnum 10K
Magnum 6K