PT-2019-5790 · Cdata · Cdata
Alexandre Torres
+2
·
Published
2019-12-27
·
Updated
2021-03-11
·
CVE-2020-29061
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CDATA devices versions 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, FD8000
Description
The issue is related to a default root password for the root account, which could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. There is a default root126 password for the root account.
Recommendations
For all affected versions, change the default root password to a strong and unique password to prevent unauthorized access.
As a temporary workaround, consider restricting access to the root account until a patch is available.
Avoid using the default root126 password in the affected devices until the issue is resolved.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cdata