Quantum DXi V1000 Static SSH Key Security Weakness
BID:66267
Info
Quantum DXi V1000 Static SSH Key Security Weakness
| Bugtraq ID: | 66267 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2014 12:00AM |
| Updated: | Mar 17 2014 12:00AM |
| Credit: | xistence |
| Vulnerable: |
Quantum DXi V1000 2.2.1 |
| Not Vulnerable: |
Quantum DXi V1000 2.3.0.1 |
Discussion
Quantum DXi V1000 Static SSH Key Security Weakness
Quantum DXi V1000 is prone to a static SSH key security weakness.
An attacker may bypass certain security restrictions and gain root access to the affected device.
Quantum DXi V1000 running firmware version 2.2.1 is vulnerable; other versions may also be affected.
Quantum DXi V1000 is prone to a static SSH key security weakness.
An attacker may bypass certain security restrictions and gain root access to the affected device.
Quantum DXi V1000 running firmware version 2.2.1 is vulnerable; other versions may also be affected.
Exploit / POC
Quantum DXi V1000 Static SSH Key Security Weakness
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
Quantum DXi V1000 Static SSH Key Security Weakness
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.