ID

VAR-E-201703-1166


CVE

cve_id:CVE-2016-10306

Trust: 0.3

sources: BID: 97241

TITLE

Trango Altum AC600 Devices CVE-2016-10306 Insecure Default Password Vulnerability

Trust: 0.3

sources: BID: 97241

DESCRIPTION

Trango Altum AC600 Devices are prone to an insecure default-password vulnerability.
Remote attackers with knowledge of the default credentials may exploit this vulnerability to gain unauthorized access and perform unauthorized actions. This may aid in further attacks.
All Trango Altum AC600 Devices are vulnerable.

Trust: 0.3

sources: BID: 97241

AFFECTED PRODUCTS

vendor:trangomodel:systems altum ac600scope:eqversion:0

Trust: 0.3

sources: BID: 97241

EXPLOIT

The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.

Trust: 0.3

sources: BID: 97241

PRICE

Free

Trust: 0.3

sources: BID: 97241

TYPE

Design Error

Trust: 0.3

sources: BID: 97241

CREDITS

iancaling.

Trust: 0.3

sources: BID: 97241

EXTERNAL IDS

db:NVDid:CVE-2016-10306

Trust: 0.3

db:BIDid:97241

Trust: 0.3

sources: BID: 97241

REFERENCES

url:http://blog.iancaling.com/post/153011925478/trango-systems-hidden-root-account-vulnerability

Trust: 0.3

url:https://www.trangosys.com/products/altum-series/

Trust: 0.3

url:http://blog.iancaling.com/post/155395764003/trango-altum-ac600-default-root-login

Trust: 0.3

sources: BID: 97241

SOURCES

db:BIDid:97241

LAST UPDATE DATE

2022-07-27T09:40:03.021000+00:00


SOURCES UPDATE DATE

db:BIDid:97241date:2017-04-04T00:02:00

SOURCES RELEASE DATE

db:BIDid:97241date:2017-03-29T00:00:00