PT-2024-5339 · Joyent+1 · Smartos+1

Edward Warren

·

Published

2024-04-08

·

Updated

2024-09-03

·

CVE-2024-39345

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AdTran 834-5 HDC17600021F1 (SmartOS) versions 11.1.1.1 through 12.5.5.0
Description The issue concerns a hidden, undocumented, hard-coded support account in AdTran 834-5 devices, whose password is based on the device's MAC address. Since all internet interfaces share a similar MAC address that only varies in the final octet, network-adjacent attackers can derive the support user's SSH password by decrementing the final octet of the connected gateway address or via the BSSID. This allows attackers to execute arbitrary OS commands with root-level privileges.
Recommendations For versions prior to 12.5.5.1, update to SmartOS 12.5.5.1 to resolve the issue. As a temporary workaround, consider disabling the SSH service until a patch is available. Restrict access to the device's internet interfaces to minimize the risk of exploitation. Avoid using the default support account until the issue is resolved.

Exploit

Fix

Using Hardcoded Credentials

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-05968
CVE-2024-39345

Affected Products

Adtran 834-5
Smartos