PT-2023-8987 · Akuvox · Akuvox E11

CVE-2023-0345

·

Publicado

2023-03-13

·

Atualizado

2023-03-16

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Akuvox E11 (affected versions not specified)
Description The issue is related to the Akuvox E11 secure shell (SSH) server, which is enabled by default and accessible by the root user with a password that cannot be changed by the user. This concern is associated with the use of pre-installed credentials. Exploitation of this issue may allow a remote attacker to elevate their privileges to the root level.
Recommendations For Akuvox E11, consider disabling the SSH server until a configuration change or update is available to secure the default credentials. As a temporary workaround, restrict access to the device to minimize the risk of exploitation.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-02867
CVE-2023-0345

Produtos afetados

Akuvox E11