PT-2020-12018 · Mir · Mir1000+4
Bernhard Dieber
+1
·
Published
2020-06-24
·
Updated
2020-07-06
·
CVE-2020-10269
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MiR100 (affected versions not specified)
MiR200 (affected versions not specified)
MiR250 (affected versions not specified)
MiR500 (affected versions not specified)
MiR1000 (affected versions not specified)
Description
A wireless interface in certain MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode with default and widely known SSID and passwords. This information has been available in past User Guides and manuals distributed by the vendor. The issue has been confirmed in MiR100 and MiR200, and it may also apply to other models.
Recommendations
For MiR100, consider changing the default SSID and password to secure the wireless Access Point.
For MiR200, update the wireless interface configuration to use unique and secure SSID and passwords.
For MiR250, MiR500, and MiR1000, if the issue applies, change the default wireless Access Point settings to secure credentials.
As a temporary workaround, consider disabling the WiFi Master mode until secure configurations can be implemented.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mir100
Mir1000
Mir200
Mir250
Mir500