PT-2018-10989 · Cloud Media · Cloud Media Popcorn A-200
Tomas Bortoli
·
Published
2018-06-17
·
Updated
2019-10-03
·
CVE-2018-12072
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Media Popcorn A-200 version 03-05-130708-21-POP-411-000
Description
An issue was discovered where the device is configured to provide TELNET remote access without a password, allowing an attacker to gain root access if they can connect to port 23. This allows for complete compromise of the device.
Recommendations
For Cloud Media Popcorn A-200 version 03-05-130708-21-POP-411-000, consider disabling TELNET remote access as a temporary workaround to minimize the risk of exploitation. Restrict access to port 23 to prevent unauthorized connections.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Media Popcorn A-200