PT-2018-11134 · Ecos · Ecos System Management Appliance

Franz Girlich

+2

·

Publicado

2018-06-17

·

Atualizado

2019-10-03

·

CVE-2018-12338

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ECOS System Management Appliance (aka SMA) version 5.2.68
Description The issue concerns an undocumented factory backdoor that allows the vendor to extract confidential information and manipulate security-relevant configurations. This is achieved via remote root SSH access.
Recommendations For version 5.2.68, consider restricting remote SSH access to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit the use of root SSH access to only necessary instances.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-12338

Produtos afetados

Ecos System Management Appliance