CVE-2019-12776
Summary
| CVE | CVE-2019-12776 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-07 16:29:00 UTC |
| Updated | 2019-06-10 18:50:00 UTC |
| Description | An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's authorized_keys file, enabling anyone with the associated private key to gain remote root access to all affected products. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Enttec | Datagate Mk2 | - | All | All | All |
| Hardware | Enttec | Datagate Mk2 | - | All | All | All |
| Operating System | Enttec | Datagate Mk2 Firmware | 70044 | 05032019-482 | All | All |
| Operating System | Enttec | Datagate Mk2 Firmware | 70044 | 05032019-482 | All | All |
| Hardware | Enttec | E-streamer Mk2 | - | All | All | All |
| Hardware | Enttec | E-streamer Mk2 | - | All | All | All |
| Operating System | Enttec | E-streamer Mk2 Firmware | 70044 | 05032019-482 | All | All |
| Operating System | Enttec | E-streamer Mk2 Firmware | 70044 | 05032019-482 | All | All |
| Hardware | Enttec | Pixelator | - | All | All | All |
| Hardware | Enttec | Pixelator | - | All | All | All |
| Operating System | Enttec | Pixelator Firmware | 70044 | 05032019-482 | All | All |
| Operating System | Enttec | Pixelator Firmware | 70044 | 05032019-482 | All | All |
| Hardware | Enttec | Storm 24 | - | All | All | All |
| Hardware | Enttec | Storm 24 | - | All | All | All |
| Operating System | Enttec | Storm 24 Firmware | 70044 | 05032019-482 | All | All |
| Operating System | Enttec | Storm 24 Firmware | 70044 | 05032019-482 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mogozobo » (0-days) ENTTEC Lighting Controllers Vulnerabilities | MISC | www.mogozobo.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.