PT-2015-6358 · Belden Garrettcom · Magnum 6K+1
Ashish Kamble
+1
·
Published
2015-08-04
·
Updated
2016-12-06
·
CVE-2015-3959
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Belden GarrettCom Magnum 6K and Magnum 10K switches firmware versions prior to 4.5.6
Description
The issue concerns a hardcoded serial-console password for a privileged account in the firmware of the affected switches. This might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation where this account is enabled, and leveraging knowledge of this password.
Recommendations
For firmware versions prior to 4.5.6, update to version 4.5.6 or later to resolve the issue. As a temporary workaround, consider disabling the privileged account with the hardcoded serial-console password until a patch is available. Restrict physical access to the switches to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Magnum 10K
Magnum 6K