PT-1998-1212 · Nbase · Nh215+1
Published
1998-07-20
·
Updated
2016-10-18
·
CVE-1999-1421
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NBase switches NH208 and NH215
Description
The issue allows remote attackers to send software updates to the switch, potentially modifying it or causing a denial of service by guessing the target filenames, which have default names.
Recommendations
For NBase switches NH208 and NH215, consider restricting access to the TFTP server to prevent unauthorized software updates until a patch is available.
As a temporary workaround, changing the default filenames of the target software updates may help minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nh208
Nh215