PT-2018-5428 · Planex · Planex Cs-W50Hd

Kenney Lu

·

Publicado

2018-08-24

·

Atualizado

2018-11-21

·

CVE-2017-12574

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: PLANEX CS-W50HD devices with firmware prior to 030720
Description: A hardcoded credential supervisor:dangerous is injected into the web authentication database /.htpasswd during the booting process, allowing attackers to gain unauthorized access and control the device completely. The account cannot be modified or deleted.
Recommendations: For PLANEX CS-W50HD devices with firmware prior to 030720, update the firmware to version 030720 or later to remove the hardcoded credential. As a temporary workaround, consider restricting access to the device until the firmware can be updated.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-12574

Produtos afetados

Planex Cs-W50Hd