RSS   Vulnerabilities for 'System management appliance'   RSS

2018-06-17
 
CVE-2018-12338

CWE-noinfo
 

 
Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipulate security relevant configurations via remote root SSH access.

 
 
CVE-2018-12335

CWE-732
 

 
Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configurations, via unrestricted database access during Easy Enrollment.

 
 
CVE-2018-12331

CWE-287
 

 
Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the-middle attacker to compromise authentication keys and configurations via IP spoofing during "Easy Enrollment."

 

 >>> Vendor: ECOS 3 Products
Embedded web servers
Secure boot stick firmware
System management appliance


Copyright 2024, cxsecurity.com

 

Back to Top