PT-2021-17982 · Bab Technologie Gmbh · Eibport V3

Psytester

·

Published

2021-09-09

·

Updated

2021-09-20

·

CVE-2021-28912

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: BAB TECHNOLOGIE GmbH eibPort V3
Description: The issue concerns a hard-coded and weak root SSH key passphrase, known as 'eibPort string', which is unique to each device. This passphrase can be used to gain SSH root access, representing the final part of an attack chain.
Recommendations: For BAB TECHNOLOGIE GmbH eibPort V3, consider changing the hard-coded root SSH key passphrase to a strong and unique password to prevent unauthorized access. As a temporary workaround, restrict SSH access to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28912

Affected Products

Eibport V3