PT-2020-9921 · Meinberg · Meinberg Syncbox/Ptp/Ptpv2
Published
2020-01-21
·
Updated
2020-01-29
·
CVE-2019-17584
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Meinberg SyncBox/PTP/PTPv2 versions prior to v5.34o, v5.34s, v5.32* or 5.34g
Description
The issue concerns default SSH keys in the devices, which can be exploited by attackers to gain root access. The private key is also utilized in an internal interface of another Meinberg device and can be extracted from a firmware update of this device.
Recommendations
For versions up to v5.34o, update to a version newer than v5.34o.
For versions up to v5.34s, update to a version newer than v5.34s.
For versions v5.32*, update to a version newer than v5.32*.
For version 5.34g, update to a version newer than 5.34g.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Meinberg Syncbox/Ptp/Ptpv2