PT-2020-10318 · Nec · Nec Sv9100

Published

2020-07-29

·

Updated

2020-08-06

·

CVE-2019-20025

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NEC SV9100 software versions 6.0 and higher
Description The issue is due to an undocumented user account with manufacturer privilege level, allowing an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password. An attacker could exploit this by using the account to remotely log into an affected device, potentially gaining manufacturer level access.
Recommendations For NEC SV9100 software versions 6.0 and higher, consider disabling the undocumented user account with manufacturer privilege level as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20025

Affected Products

Nec Sv9100