PT-2016-3203 · Openelec+1 · Openelec+1
Cyclotron3Ko
·
Published
2016-02-02
·
Updated
2016-02-25
·
CVE-2016-2230
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenELEC (affected versions not specified)
RasPlex (affected versions not specified)
Description
The issue is related to a hardcoded password for the root account in OpenELEC and RasPlex devices, making it easier for remote attackers to obtain access via an SSH session. This allows a remote attacker to exploit the vulnerability and gain access to the device using the SSH protocol.
Recommendations
For OpenELEC, consider changing the hardcoded root password to a unique and secure password as a temporary workaround.
For RasPlex, restrict access to the root account until a more permanent solution is available.
As a general mitigation measure, restrict SSH access to only necessary users and consider disabling the root account for SSH access to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openelec
Rasplex