PT-2017-13259 · Arris · Arris Nvg589+1

Publicado

2017-09-03

·

Atualizado

2021-08-23

·

CVE-2017-14115

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Arris NVG589 and NVG599 devices version 9.2.2h0d83
Description The firmware configures ssh-permanent-enable WAN SSH logins to the remotessh account with the 5SaP9I26 password when IP Passthrough mode is not used. This allows remote attackers to access a "Terminal shell v1.0" service and obtain unrestricted root privileges by establishing an SSH session and entering certain shell metacharacters and BusyBox commands.
Recommendations For version 9.2.2h0d83, consider disabling the WAN SSH logins to the remotessh account until a patch is available. Restrict access to the SSH service to minimize the risk of exploitation. Avoid using the default password 5SaP9I26 for the remotessh account.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14115

Produtos afetados

Arris Nvg589
Arris Nvg599