PT-2021-22916 · Airangel · Airangel Hsmx Gateway
Published
2021-11-10
·
Updated
2021-11-12
·
CVE-2021-40519
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Airangel HSMX Gateway devices versions 5.2.04 and earlier
Description
The issue concerns hard-coded database credentials in the affected devices. This could potentially allow unauthorized access to the database.
Recommendations
For Airangel HSMX Gateway devices versions 5.2.04 and earlier, update to a version later than 5.2.04 to resolve the issue.
As a temporary workaround, consider restricting access to the database to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airangel Hsmx Gateway