PT-2018-11134 · Ecos · Ecos System Management Appliance
Franz Girlich
+2
·
Published
2018-06-17
·
Updated
2019-10-03
·
CVE-2018-12338
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ECOS System Management Appliance (aka SMA) version 5.2.68
Description
The issue concerns an undocumented factory backdoor that allows the vendor to extract confidential information and manipulate security-relevant configurations. This is achieved via remote root SSH access.
Recommendations
For version 5.2.68, consider restricting remote SSH access to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit the use of root SSH access to only necessary instances.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ecos System Management Appliance