PT-2021-17982 · Bab Technologie Gmbh · Eibport V3
Psytester
·
Published
2021-09-09
·
Updated
2021-09-20
·
CVE-2021-28912
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
BAB TECHNOLOGIE GmbH eibPort V3
Description:
The issue concerns a hard-coded and weak root SSH key passphrase, known as 'eibPort string', which is unique to each device. This passphrase can be used to gain SSH root access, representing the final part of an attack chain.
Recommendations:
For BAB TECHNOLOGIE GmbH eibPort V3, consider changing the hard-coded root SSH key passphrase to a strong and unique password to prevent unauthorized access. As a temporary workaround, restrict SSH access to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eibport V3