PT-2019-3540 · Zingbox · Zingbox Inspector

CVE-2019-15017

·

Publicado

2019-10-01

·

Atualizado

2023-02-04

CVSS v3.1

8.4

Alta

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zingbox Inspector versions 1.294 and earlier
Description The issue is related to the SSH service being enabled, exposing it to the local network. This, combined with other factors, can allow an attacker to authenticate to the service using hardcoded credentials. The vulnerability is associated with the use of predefined credentials, which can be exploited by a remote attacker to gain unauthorized access to the SSH service as the root user.
Recommendations For Zingbox Inspector versions 1.294 and earlier, consider disabling the SSH service to prevent exploitation until a patch is available. Restrict access to the SSH service to minimize the risk of unauthorized access. Avoid using predefined credentials for the SSH service.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-03717
CVE-2019-15017

Produtos afetados

Zingbox Inspector