PT-2017-18719 · Ceragon · Ceragon Fibeair Ip-10

Published

2017-05-21

·

Updated

2019-10-03

·

CVE-2017-9137

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ceragon FibeAir IP-10 wireless radios versions through 7.2.0
Description The issue concerns a default password for a hidden user account named mateidu. This account can be accessed through both the web interface and SSH. While the web interface provides read-only access to device settings, SSH access grants a Linux shell. The vendor has noted that customers are instructed to change the mateidu user password, which fully resolves the issue.
Recommendations For versions through 7.2.0, change the mateidu user password to fully solve the vulnerability.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9137

Affected Products

Ceragon Fibeair Ip-10