Lucene search

K
cveMitreCVE-2011-0885
HistoryFeb 08, 2011 - 10:00 p.m.

CVE-2011-0885

2011-02-0822:00:02
CWE-255
mitre
web.nvd.nist.gov
28
cve-2011-0885
comcast business gateway
smc smcd3g-ccr
firmware
default password
remote attackers
administrative access
web interface
telnet interface
security vulnerability
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.019

Percentile

88.9%

A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme for the mso account, which makes it easier for remote attackers to obtain administrative access via the (1) web interface or (2) TELNET interface.

Affected configurations

Nvd
Node
smc_networkssmcd3g-ccr
AND
smc_networkssmcd3g-ccr_firmwareRange1.4.0.49
OR
smc_networkssmcd3g-ccr_firmwareMatch1.4.0.42
VendorProductVersionCPE
smc_networkssmcd3g-ccr*cpe:2.3:h:smc_networks:smcd3g-ccr:*:*:*:*:*:*:*:*
smc_networkssmcd3g-ccr_firmware*cpe:2.3:a:smc_networks:smcd3g-ccr_firmware:*:*:*:*:*:*:*:*
smc_networkssmcd3g-ccr_firmware1.4.0.42cpe:2.3:a:smc_networks:smcd3g-ccr_firmware:1.4.0.42:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.019

Percentile

88.9%