PT-2020-12615 · Technicolor · Technicolor Tc7337

Published

2020-04-01

·

Updated

2020-04-02

·

CVE-2020-11449

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Technicolor TC7337 version 8.89.17
Description An issue allows an attacker to discover admin credentials in the backup file, specifically the backupsettings.conf file.
Recommendations For Technicolor TC7337 version 8.89.17, consider restricting access to the backup file to minimize the risk of exploitation. As a temporary workaround, limit access to sensitive areas of the device until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11449

Affected Products

Technicolor Tc7337