PT-2017-17651 · Riverbed · Riverbed Rios
CVE-2017-7305
·
Publicado
2017-04-04
·
Atualizado
2024-08-05
CVSS v3.1
4.6
Média
| Vetor | AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Riverbed RiOS versions prior to 9.6.1
Description
The issue allows physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot because a bootloader password is not required. The product contains correct computational logic for a bootloader password; however, this password is optional to meet different customers' needs.
Recommendations
For Riverbed RiOS versions prior to 9.6.1, consider setting a bootloader password to enhance security, as the absence of this password can facilitate attacks on the secure-vault protection mechanism.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Riverbed Rios