OptiSwitch 400/800 Unauthorized Remote Access Vulnerability
BID:8036
Info
OptiSwitch 400/800 Unauthorized Remote Access Vulnerability
| Bugtraq ID: | 8036 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2003 12:00AM |
| Updated: | Jun 25 2003 12:00AM |
| Credit: | This vulnerability was reported by [email protected]. |
| Vulnerable: |
MRV Communications OptiSwitch 800 MRV Communications OptiSwitch 400 |
| Not Vulnerable: | |
Discussion
OptiSwitch 400/800 Unauthorized Remote Access Vulnerability
A vulnerability has been reported for the OptiSwitch device which could allow an attacker to gain unauthorized remote access. The problem occurs when a specific sequence of key presses are initiated by a remote user, when connected to the device via telnet or the console.
When the sequence is processed, remote access will be granted to the attacker.
*** The vendor has responded and has reported that the vulnerability does not infact exist.
A vulnerability has been reported for the OptiSwitch device which could allow an attacker to gain unauthorized remote access. The problem occurs when a specific sequence of key presses are initiated by a remote user, when connected to the device via telnet or the console.
When the sequence is processed, remote access will be granted to the attacker.
*** The vendor has responded and has reported that the vulnerability does not infact exist.
Exploit / POC
OptiSwitch 400/800 Unauthorized Remote Access Vulnerability
No exploit required.
No exploit required.
Solution / Fix
OptiSwitch 400/800 Unauthorized Remote Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
OptiSwitch 400/800 Unauthorized Remote Access Vulnerability
References:
References:
- OptiSwitch Product Page (MRV Communications)
- OptiSwitch remote root compromise (CrazZzy Slash
)