PT-2017-16571 · Fiberhome · Fiberhome Fengine S5800
Publicado
2017-01-23
·
Atualizado
2021-09-09
·
CVE-2017-5544
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FiberHome Fengine S5800 switches version V210R240
Description
An issue allows an unauthorized attacker to access the device's SSH service using a password cracking tool, leading to a denial of service. The repeated login attempts will occupy connection slots for a longer time, causing legitimate login attempts via SSH/telnet to be refused. This issue can be triggered by exploiting the SSH login, resulting in a denial of service that requires a device restart.
Recommendations
For FiberHome Fengine S5800 switches version V210R240, consider restricting access to the SSH service as a temporary workaround until a patch is available. Additionally, monitor SSH login attempts and implement measures to prevent brute-force attacks, such as limiting the number of concurrent connections or implementing rate limiting on SSH login attempts.
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fiberhome Fengine S5800