Lucene search

K
jvnJapan Vulnerability NotesJVN:71349007
HistoryNov 04, 2011 - 12:00 a.m.

JVN#71349007: Opengear console servers vulnerable to authentication bypass

2011-11-0400:00:00
Japan Vulnerability Notes
jvn.jp
21

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.005

Percentile

77.5%

Opengear console servers are for managing servers and network products. Opengear console servers contain an authentication bypass vulnerability.

Impact

A remote attacker may change the settings in the Opengear console server or gain access to products that are connected to the console server.

Solution

Update the Firmware
Update to the latest version of the firmware, according to the information provided by the developer.

According to the developer, this vulnerability was addressed in firmware version 2.2.1.

Products Affected

  • Opengear console server firmware versions prior to 2.2.1
    Console servers that use the above firmware versions are vulnerable.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.005

Percentile

77.5%

Related for JVN:71349007