PT-2002-2657 · Utstarcom · Utstarcom Bas 1000

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1936

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions UTStarcom BAS 1000 version 3.1.10
Description The issue allows remote attackers to gain access due to the presence of default or back door accounts and passwords. Specifically, the affected accounts and passwords are: (1) field account with a password of *field, (2) guru account with a password of *3noguru, (3) snmp account with a password of snmp, or (4) dbase account with a password of dbase.
Recommendations For UTStarcom BAS 1000 version 3.1.10, consider changing the default passwords for the field, guru, snmp, and dbase accounts to prevent unauthorized access. As a temporary workaround, restrict access to these accounts until a more permanent solution is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1936

Affected Products

Utstarcom Bas 1000