Vulnerability CVE-2019-12776


Published: 2019-06-07

Description:
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's authorized_keys file, enabling anyone with the associated private key to gain remote root access to all affected products.

Type:

CWE-798

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Enttec -> Datagate mk2 firmware 
Enttec -> E-streamer mk2 firmware 
Enttec -> Pixelator firmware 
Enttec -> Storm 24 firmware 

 References:
https://www.mogozobo.com/?p=3476

Copyright 2024, cxsecurity.com

 

Back to Top