PT-2022-23497 · Eclipse · Eclipse Tcf

James A. Chambers

·

Published

2022-09-01

·

Updated

2022-09-08

·

CVE-2022-36601

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JasMiner-X4-Server versions 20220621-090907 and below
Description The Eclipse TCF debug interface is open on port 1534, allowing unauthenticated attackers to gain root privileges on the affected device, access sensitive data, or execute arbitrary commands.
Recommendations For JasMiner-X4-Server versions 20220621-090907 and below, consider disabling the Eclipse TCF debug interface on port 1534 as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2022-36601

Affected Products

Eclipse Tcf