PT-2019-5790 · Cdata · Cdata

Alexandre Torres

+2

·

Published

2019-12-27

·

Updated

2021-03-11

·

CVE-2020-29061

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CDATA devices versions 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, FD8000
Description The issue is related to a default root password for the root account, which could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. There is a default root126 password for the root account.
Recommendations For all affected versions, change the default root password to a strong and unique password to prevent unauthorized access. As a temporary workaround, consider restricting access to the root account until a patch is available. Avoid using the default root126 password in the affected devices until the issue is resolved.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02177
CVE-2020-29061

Affected Products

Cdata