PT-2024-26405 · Sharp+1 · Multiple Mfps

Pierre Barre

+1

·

Published

2024-11-26

·

Updated

2024-12-01

·

CVE-2024-35244

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions No specific product names, model numbers, or versions are mentioned in the provided descriptions.
Description There are several hidden accounts, some of which are intended for maintenance engineers. With knowledge of their passwords, these accounts can be used to re-configure the device. The passwords can be obtained by examining the coredump.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-35244

Affected Products

Multiple Mfps