PT-2015-6358 · Belden Garrettcom · Magnum 6K+1

Ashish Kamble

+1

·

Published

2015-08-04

·

Updated

2016-12-06

·

CVE-2015-3959

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Belden GarrettCom Magnum 6K and Magnum 10K switches firmware versions prior to 4.5.6
Description The issue concerns a hardcoded serial-console password for a privileged account in the firmware of the affected switches. This might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation where this account is enabled, and leveraging knowledge of this password.
Recommendations For firmware versions prior to 4.5.6, update to version 4.5.6 or later to resolve the issue. As a temporary workaround, consider disabling the privileged account with the hardcoded serial-console password until a patch is available. Restrict physical access to the switches to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-3959

Affected Products

Magnum 10K
Magnum 6K