PT-2021-17983 · Unknown · Eibport V3
Psytester
·
Published
2021-09-09
·
Updated
2021-09-20
·
CVE-2021-28913
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
eibPort V3 versions prior to 3.9.1
Description:
The issue allows unauthenticated attackers to access the /webif/SecurityModule to validate the hard-coded unique 'eibPort String', which acts as the root SSH key passphrase. This can be part of an attack chain to gain SSH root access.
Recommendations:
For versions prior to 3.9.1, update to version 3.9.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the /webif/SecurityModule endpoint until a patch is available.
Avoid using the hard-coded
eibPort String as the root SSH key passphrase in the affected versions.Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eibport V3