PT-2019-14225 · Blackbox+1 · Black Box Icompel+1
Frank Barton
·
Publicado
2019-08-26
·
Atualizado
2019-09-04
·
CVE-2019-15497
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Black Box iCOMPEL versions 9.2.3 through 11.1.4
ONELAN Net-Top-Box versions 9.2.3 through 11.1.4
Description
The issue allows remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP due to default credentials.
Recommendations
For Black Box iCOMPEL versions 9.2.3 through 11.1.4, change the default credentials to secure ones.
For ONELAN Net-Top-Box versions 9.2.3 through 11.1.4, change the default credentials to secure ones.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Black Box Icompel
Onelan Net-Top-Box