ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.tarlogic.com/advisories/Tarlogic-2018-002.txt |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-04-11T17:00:00Z
Updated: 2024-09-17T03:13:37.016Z
Reserved: 2018-04-11T00:00:00Z
Link: CVE-2018-10024
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-04-11T17:29:00.397
Modified: 2024-11-21T03:40:41.820
Link: CVE-2018-10024
Redhat
No data.