PT-2021-20358 · Lancom · Lcos

Thomas Stimper

·

Published

2021-10-07

·

Updated

2021-10-15

·

CVE-2021-33903

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LANCOM devices LCOS versions 10.40 through 10.42.0473-RU3
Description: The issue arises when the password of the root user is changed via the CLI in LCOS versions 10.40 to 10.42.0473-RU3 with SNMPv3 enabled on LANCOM devices. This change does not update the password for SNMPv3 access. However, changing the root user's password via LANconfig does successfully update the SNMPv3 password.
Recommendations: For LCOS versions 10.40 through 10.42.0473-RU3, consider changing the root user's password via LANconfig instead of the CLI to ensure the SNMPv3 password is updated correctly. As a temporary workaround, restrict SNMPv3 access until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-33903

Affected Products

Lcos