PT-2016-6977 · Aver Information · Aver Information Eh6108H+

Travis Lee

·

Publicado

2016-09-19

·

Atualizado

2016-11-28

·

CVE-2016-6535

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AVer Information EH6108H+ devices with firmware X9.03.24.00.07l
Description The issue allows remote attackers to obtain root access by leveraging knowledge of hardcoded account credentials and establishing a TELNET session.
Recommendations For AVer Information EH6108H+ devices with firmware X9.03.24.00.07l, consider disabling TELNET access as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6535

Produtos afetados

Aver Information Eh6108H+