PT-2018-11134 · Ecos · Ecos System Management Appliance

Franz Girlich

+2

·

Published

2018-06-17

·

Updated

2019-10-03

·

CVE-2018-12338

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ECOS System Management Appliance (aka SMA) version 5.2.68
Description The issue concerns an undocumented factory backdoor that allows the vendor to extract confidential information and manipulate security-relevant configurations. This is achieved via remote root SSH access.
Recommendations For version 5.2.68, consider restricting remote SSH access to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit the use of root SSH access to only necessary instances.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-12338

Affected Products

Ecos System Management Appliance