PT-2017-7167 · Zte · Hg110+5

Publicado

2017-08-29

·

Atualizado

2017-09-12

·

CVE-2015-7255

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZTE OX-330P ZXHN H108N W300V1.0.0S ZRD TR1 D68 HG110 GAN9.8T101A-B MF28G ZXHN H108N
Description The issue allows remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device, as the devices use non-unique X.509 certificates and SSH host keys.
Recommendations For ZTE OX-330P, update the X.509 certificates and SSH host keys to unique values. For ZXHN H108N, update the X.509 certificates and SSH host keys to unique values. For W300V1.0.0S ZRD TR1 D68, update the X.509 certificates and SSH host keys to unique values. For HG110, update the X.509 certificates and SSH host keys to unique values. For GAN9.8T101A-B, update the X.509 certificates and SSH host keys to unique values. For MF28G, update the X.509 certificates and SSH host keys to unique values. As a temporary workaround, consider restricting access to sensitive information until unique X.509 certificates and SSH host keys are implemented.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7255

Produtos afetados

Gan9.8T101A-B
Hg110
Mf28G
W300V1.0.0S Zrd Tr1 D68
Zte Ox-330P
Zxhn H108N