PT-2024-11747 · Siklu · Siklu Tg Terragraph

Semaja2Semaja2

·

Published

2024-03-17

·

Updated

2024-08-01

·

CVE-2022-47037

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Siklu TG Terragraph devices versions prior to 2.1.1
Description The issue allows attackers to discover valid, randomly generated credentials via the GetCredentials endpoint. This can potentially lead to unauthorized access.
Recommendations For versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the GetCredentials endpoint until a patch is available.

Exploit

Fix

Improper Access Control

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-47037

Affected Products

Siklu Tg Terragraph