PT-2017-7167 · Zte · Hg110+5
Publicado
2017-08-29
·
Atualizado
2017-09-12
·
CVE-2015-7255
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ZTE OX-330P
ZXHN H108N
W300V1.0.0S ZRD TR1 D68
HG110
GAN9.8T101A-B
MF28G
ZXHN H108N
Description
The issue allows remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device, as the devices use non-unique X.509 certificates and SSH host keys.
Recommendations
For ZTE OX-330P, update the X.509 certificates and SSH host keys to unique values.
For ZXHN H108N, update the X.509 certificates and SSH host keys to unique values.
For W300V1.0.0S ZRD TR1 D68, update the X.509 certificates and SSH host keys to unique values.
For HG110, update the X.509 certificates and SSH host keys to unique values.
For GAN9.8T101A-B, update the X.509 certificates and SSH host keys to unique values.
For MF28G, update the X.509 certificates and SSH host keys to unique values.
As a temporary workaround, consider restricting access to sensitive information until unique X.509 certificates and SSH host keys are implemented.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gan9.8T101A-B
Hg110
Mf28G
W300V1.0.0S Zrd Tr1 D68
Zte Ox-330P
Zxhn H108N