PT-2022-3084 · Motorola · Motorola Ace1000 Rtu

Daniel Dos Santos

+1

·

Published

2022-06-22

·

Updated

2024-08-01

·

CVE-2022-30271

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Motorola ACE1000 RTU through 2022-05-02
Description The issue is related to the use of hardcoded SSH credentials. This could allow a remote attacker to gain unauthorized access to protected information. The hardcoded SSH private key is likely to be used by default due to the initialization scripts, such as /etc/init.d/sshd service, only generating a new key if no private-key file exists.
Recommendations For Motorola ACE1000 RTU through 2022-05-02, consider regenerating the SSH private key to prevent the use of the hardcoded key. As a temporary workaround, restrict access to the SSH service until a more permanent solution can be applied.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-03754
CVE-2022-30271

Affected Products

Motorola Ace1000 Rtu