Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in newer hardware, which would typically be used with firmware 2.1.1 or later.
History

Tue, 27 Aug 2024 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-03-18T00:00:00

Updated: 2024-08-27T16:18:46.526Z

Reserved: 2022-12-12T00:00:00

Link: CVE-2022-47036

cve-icon Vulnrichment

Updated: 2024-08-03T14:47:28.392Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-18T03:15:05.957

Modified: 2024-08-27T17:35:01.233

Link: CVE-2022-47036

cve-icon Redhat

No data.