PT-2013-2123 · Digital Alert Systems+1 · Dasdec+1
Cesar Cerrudo
+1
·
Published
2013-06-29
·
Updated
2020-01-29
·
CVE-2013-0137
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Digital Alert Systems DASDEC EAS device versions prior to 2.0-2
Monroe Electronics R189 One-Net EAS device versions prior to 2.0-2
Description
The default configuration of the affected devices contains a known SSH private key, allowing remote attackers to obtain root access and spoof alerts via an SSH session.
Recommendations
For Digital Alert Systems DASDEC EAS device versions prior to 2.0-2, update to version 2.0-2 or later to resolve the issue.
For Monroe Electronics R189 One-Net EAS device versions prior to 2.0-2, update to version 2.0-2 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dasdec
R189 One-Net