RioRey RIOS Hardcoded Password Security Bypass Vulnerability
BID:42349
Info
RioRey RIOS Hardcoded Password Security Bypass Vulnerability
| Bugtraq ID: | 42349 |
| Class: | Design Error |
| CVE: |
CVE-2009-3710 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2009 12:00AM |
| Updated: | Oct 07 2009 12:00AM |
| Credit: | Marek Kroemeke |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
RioRey RIOS Hardcoded Password Security Bypass Vulnerability
RioRey RIOS is prone to a security-bypass vulnerability caused by hard-coded default passwords.
Successful attacks can allow a remote attacker to gain access to the vulnerable device.
RioRey RIOS versions 4.6.6 and 4.7.0 are vulnerable; other versions may also be affected.
RioRey RIOS is prone to a security-bypass vulnerability caused by hard-coded default passwords.
Successful attacks can allow a remote attacker to gain access to the vulnerable device.
RioRey RIOS versions 4.6.6 and 4.7.0 are vulnerable; other versions may also be affected.
Exploit / POC
RioRey RIOS Hardcoded Password Security Bypass Vulnerability
An attacker can carry out this attack using readily available network utilities.
An attacker can carry out this attack using readily available network utilities.
Solution / Fix
RioRey RIOS Hardcoded Password Security Bypass Vulnerability
Solution:
Reports indicate that this issue has been fixed by the vendor but Symantec has not confirmed it. Please contact the vendor for more information.
Solution:
Reports indicate that this issue has been fixed by the vendor but Symantec has not confirmed it. Please contact the vendor for more information.