PT-2018-11134 · Ecos · Ecos System Management Appliance

·

CVE-2018-12338

·

Published

2018-06-17

·

Updated

2019-10-03

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ECOS System Management Appliance (aka SMA) version 5.2.68
Description The issue concerns an undocumented factory backdoor that allows the vendor to extract confidential information and manipulate security-relevant configurations. This is achieved via remote root SSH access.
Recommendations For version 5.2.68, consider restricting remote SSH access to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit the use of root SSH access to only necessary instances.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-12338

Affected Products

Ecos System Management Appliance