Lucene search

K
cveMitreCVE-2012-4577
HistoryAug 21, 2012 - 6:55 p.m.

CVE-2012-4577

2012-08-2118:55:01
CWE-255
mitre
web.nvd.nist.gov
31
linux firmware
korenix jetport
oring
din-rail
serial-device servers
hardcoded password
root account
remote attackers
administrative access
ssh
cve-2012-4577

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.011

Percentile

84.2%

The Linux firmware image on (1) Korenix Jetport 5600 series serial-device servers and (2) ORing Industrial DIN-Rail serial-device servers has a hardcoded password of “password” for the root account, which allows remote attackers to obtain administrative access via an SSH session.

Affected configurations

Nvd
Node
korenixjetportMatch5601
OR
korenixjetportMatch5601f
OR
korenixjetportMatch5604
OR
korenixjetportMatch5604i
VendorProductVersionCPE
korenixjetport5601cpe:2.3:h:korenix:jetport:5601:*:*:*:*:*:*:*
korenixjetport5601fcpe:2.3:h:korenix:jetport:5601f:*:*:*:*:*:*:*
korenixjetport5604cpe:2.3:h:korenix:jetport:5604:*:*:*:*:*:*:*
korenixjetport5604icpe:2.3:h:korenix:jetport:5604i:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.011

Percentile

84.2%

Related for CVE-2012-4577