PT-2017-16571 · Fiberhome · Fiberhome Fengine S5800

Published

2017-01-23

·

Updated

2021-09-09

·

CVE-2017-5544

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FiberHome Fengine S5800 switches version V210R240
Description An issue allows an unauthorized attacker to access the device's SSH service using a password cracking tool, leading to a denial of service. The repeated login attempts will occupy connection slots for a longer time, causing legitimate login attempts via SSH/telnet to be refused. This issue can be triggered by exploiting the SSH login, resulting in a denial of service that requires a device restart.
Recommendations For FiberHome Fengine S5800 switches version V210R240, consider restricting access to the SSH service as a temporary workaround until a patch is available. Additionally, monitor SSH login attempts and implement measures to prevent brute-force attacks, such as limiting the number of concurrent connections or implementing rate limiting on SSH login attempts.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5544

Affected Products

Fiberhome Fengine S5800