PT-2022-23497 · Eclipse · Eclipse Tcf
James A. Chambers
·
Published
2022-09-01
·
Updated
2022-09-08
·
CVE-2022-36601
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JasMiner-X4-Server versions 20220621-090907 and below
Description
The Eclipse TCF debug interface is open on port 1534, allowing unauthenticated attackers to gain root privileges on the affected device, access sensitive data, or execute arbitrary commands.
Recommendations
For JasMiner-X4-Server versions 20220621-090907 and below, consider disabling the Eclipse TCF debug interface on port 1534 as a temporary workaround to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Tcf