Nexans FTTO GigaSwitch industrial/office switches default account | CVE-2022-32985
NAME
Nexans FTTO GigaSwitch industrial/office switches default account
- Platforms Affected:
Nexans FTTO GigaSwitch HW Version 5 Firmware 6.02L
Nexans FTTO GigaSwitch HW Version 5 Firmware 5.04M - Risk Level:
9.8 - Exploitability:
Unproven - Consequences:
Gain Access
DESCRIPTION
Nexans FTTO GigaSwitch industrial/office switche contains default hardcoded root user in “/etc/passwd”. A remote attacker could exploit this vulnerability to gain (root) access to the device.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Upgrade to the latest version of Nexans FTTO GigaSwitch industrial/office switches (6.02, 7.02 or later), available from the Nexans Web site. See References.
- Reference Link:
https://seclists.org/fulldisclosure/2022/Jun/36 - Reference Link:
https://www.nexans-ans.de/support/firmware/
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.