PT-2022-21056 · Oring · Oring Net Iap-420

Lorenzo Bazzana

+2

·

Published

2022-10-21

·

Updated

2022-12-07

·

CVE-2022-3203

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ORing net IAP-420(+) version 2.0m
Description The issue allows unauthorized access to the device via telnet, using hardcoded credentials, which provides an administrative shell. These credentials reset to defaults with every reboot, allowing repeated unauthorized access.
Recommendations For version 2.0m, as a temporary workaround, consider restricting access to the telnet server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Hidden Functionality

Weakness Enumeration

Related Identifiers

CVE-2022-3203

Affected Products

Oring Net Iap-420