PT-2021-20358 · Lancom · Lcos
Thomas Stimper
·
Published
2021-10-07
·
Updated
2021-10-15
·
CVE-2021-33903
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
LANCOM devices LCOS versions 10.40 through 10.42.0473-RU3
Description:
The issue arises when the password of the root user is changed via the CLI in LCOS versions 10.40 to 10.42.0473-RU3 with SNMPv3 enabled on LANCOM devices. This change does not update the password for SNMPv3 access. However, changing the root user's password via LANconfig does successfully update the SNMPv3 password.
Recommendations:
For LCOS versions 10.40 through 10.42.0473-RU3, consider changing the root user's password via LANconfig instead of the CLI to ensure the SNMPv3 password is updated correctly. As a temporary workaround, restrict SNMPv3 access until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lcos