PT-2017-16571 · Fiberhome · Fiberhome Fengine S5800

Publicado

2017-01-23

·

Atualizado

2021-09-09

·

CVE-2017-5544

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FiberHome Fengine S5800 switches version V210R240
Description An issue allows an unauthorized attacker to access the device's SSH service using a password cracking tool, leading to a denial of service. The repeated login attempts will occupy connection slots for a longer time, causing legitimate login attempts via SSH/telnet to be refused. This issue can be triggered by exploiting the SSH login, resulting in a denial of service that requires a device restart.
Recommendations For FiberHome Fengine S5800 switches version V210R240, consider restricting access to the SSH service as a temporary workaround until a patch is available. Additionally, monitor SSH login attempts and implement measures to prevent brute-force attacks, such as limiting the number of concurrent connections or implementing rate limiting on SSH login attempts.

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5544

Produtos afetados

Fiberhome Fengine S5800