← Zuruck zu CVEs
CVE-2022-32985
CRITICAL9.8
Beschreibung
libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht7/17/2022
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
nexans:gigaswitch_641_desk_v5_sfp-vinexans:gigaswitch_641_desk_v5_sfp-vi_firmwarenexans:gigaswitch_642_desk_v5_sfp-2vinexans:gigaswitch_642_desk_v5_sfp-2vi_firmwarenexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdcnexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmwarenexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdcnexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmwarenexans:gigaswitch_v5_2tp_sfp-vi_54vdcnexans:gigaswitch_v5_2tp_sfp-vi_54vdc_firmwarenexans:gigaswitch_v5_sfp-2vi_230vacnexans:gigaswitch_v5_sfp-2vi_230vac_firmwarenexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdcnexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmwarenexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_indnexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmwarenexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_mednexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmwarenexans:gigaswitch_v5_tp_sfp-2vi_54vdcnexans:gigaswitch_v5_tp_sfp-2vi_54vdc_firmwarenexans:gigaswitch_v5_tp_sfp-2vi_54vdc_indnexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmwarenexans:gigaswitch_v5_tp_sfp-2vi_54vdc_mednexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmwarenexans:gigaswitch_v5_tp_sfp-vi_230vacnexans:gigaswitch_v5_tp_sfp-vi_230vac_firmware
Schwachen (CWE)
CWE-798
Referenzen
https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/(cve@mitre.org)
https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html(cve@mitre.org)
https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/(af854a3a-2127-422b-91ae-364da2661108)
https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.