PT-2020-10318 · Nec · Nec Sv9100
Published
2020-07-29
·
Updated
2020-08-06
·
CVE-2019-20025
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NEC SV9100 software versions 6.0 and higher
Description
The issue is due to an undocumented user account with manufacturer privilege level, allowing an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password. An attacker could exploit this by using the account to remotely log into an affected device, potentially gaining manufacturer level access.
Recommendations
For NEC SV9100 software versions 6.0 and higher, consider disabling the undocumented user account with manufacturer privilege level as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nec Sv9100