PT-2020-9921 · Meinberg · Meinberg Syncbox/Ptp/Ptpv2

Published

2020-01-21

·

Updated

2020-01-29

·

CVE-2019-17584

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Meinberg SyncBox/PTP/PTPv2 versions prior to v5.34o, v5.34s, v5.32* or 5.34g
Description The issue concerns default SSH keys in the devices, which can be exploited by attackers to gain root access. The private key is also utilized in an internal interface of another Meinberg device and can be extracted from a firmware update of this device.
Recommendations For versions up to v5.34o, update to a version newer than v5.34o. For versions up to v5.34s, update to a version newer than v5.34s. For versions v5.32*, update to a version newer than v5.32*. For version 5.34g, update to a version newer than 5.34g.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-17584

Affected Products

Meinberg Syncbox/Ptp/Ptpv2