PT-2011-2731 · Smc · Smc Smcd3G-Ccr
Matthew Jakubowski
+1
·
Published
2011-02-08
·
Updated
2018-10-09
·
CVE-2011-0885
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SMC SMCD3G-CCR versions prior to 1.4.0.49.2
Description
The issue allows remote attackers to gain administrative access due to a default password for the
mso account. This default password is 'D0nt4g3tme'. Attackers can exploit this via the web interface or TELNET interface.Recommendations
For versions prior to 1.4.0.49.2, update the firmware to version 1.4.0.49.2 or later to change the default password for the
mso account. As a temporary workaround, consider changing the default password for the mso account to a strong, unique password until the firmware can be updated.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smc Smcd3G-Ccr