PT-2024-5340 · Adtran · Adtran Srg 834-5
Edward Warren
·
Published
2024-04-08
·
Updated
2024-09-03
·
CVE-2024-31970
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AdTran SRG 834-5 devices with SmartOS versions prior to 12.1.3.1
Description
The issue is related to the use of hardcoded credentials in the SSH service of the affected devices. This allows a remote attacker to execute arbitrary operating system commands by exploiting a window of time during device setup when default credentials are used. The default username and password combination of
admin/admin with root-level privileges can be exploited to gain unauthorized root access. This can be achieved by either modifying the existing admin account or creating a new account with equivalent privileges.Recommendations
For AdTran SRG 834-5 devices with SmartOS versions prior to 12.1.3.1, update to Version 12.1.3.1 or later to resolve the issue. As a temporary workaround, consider changing the default
admin/admin credentials immediately after setup to prevent exploitation. Restrict access to the SSH service to minimize the risk of unauthorized access.Exploit
Fix
Improper Authorization
Using Hardcoded Credentials
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Adtran Srg 834-5