PT-2018-10989 · Cloud Media · Cloud Media Popcorn A-200

Tomas Bortoli

·

Published

2018-06-17

·

Updated

2019-10-03

·

CVE-2018-12072

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Media Popcorn A-200 version 03-05-130708-21-POP-411-000
Description An issue was discovered where the device is configured to provide TELNET remote access without a password, allowing an attacker to gain root access if they can connect to port 23. This allows for complete compromise of the device.
Recommendations For Cloud Media Popcorn A-200 version 03-05-130708-21-POP-411-000, consider disabling TELNET remote access as a temporary workaround to minimize the risk of exploitation. Restrict access to port 23 to prevent unauthorized connections.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-12072

Affected Products

Cloud Media Popcorn A-200