PT-2023-12362 · Unem+1 · Unem+1
Published
2023-01-05
·
Updated
2023-07-17
·
CVE-2021-40342
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FOXMAN-UN versions R9C through R16A
UNEM versions R9C through R16A
Description
The issue affects the DES implementation in the affected product versions, which use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements managed by the affected products.
Recommendations
For FOXMAN-UN versions R9C through R16A, consider changing the default encryption key to a unique key for each installation as a temporary workaround.
For UNEM versions R9C through R16A, consider changing the default encryption key to a unique key for each installation as a temporary workaround.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Foxmann-Un
Unem