ID
VAR-201009-0309
TITLE
Edge-corE ES4649 Switch Password Security Vulnerability
Trust: 0.6
sources:
            
            
            CNVD: CNVD-2010-1917
DESCRIPTION
Switches developed by Accton include 3Com, Dell, SMC, Foundry and EdgeCore, which have security vulnerabilities that allow malicious users to control devices. The problem is that the switch has a built-in \"__super\" user, and its password is generated based on the MAC address. The MAC address of the switch is obtained through ARP or SNMP. The management interface can be controlled through TELNET, SSH and HTTP.
Trust: 0.6
sources:
            
            
            CNVD: CNVD-2010-1917
IOT TAXONOMY
| category: | ['Network device'] | sub_category: | - | Trust: 0.6  | 
sources:
            
            
            CNVD: CNVD-2010-1917
AFFECTED PRODUCTS
| vendor: | accton | model: | edge-core es4649 switch | scope: | - | version: | - | Trust: 0.6  | 
sources:
            
            
            CNVD: CNVD-2010-1917
EXTERNAL IDS
| db: | EXPLOIT-DB | id: | 14875 | Trust: 0.6  | 
| db: | CNVD | id: | CNVD-2010-1917 | Trust: 0.6  | 
sources:
            
            
            CNVD: CNVD-2010-1917
REFERENCES
| url: | http://www.exploit-db.com/exploits/14875/http | Trust: 0.6  | 
sources:
            
            
            CNVD: CNVD-2010-1917
SOURCES
| db: | CNVD | id: | CNVD-2010-1917 | 
LAST UPDATE DATE
2022-05-17T02:09:16.577000+00:00
SOURCES UPDATE DATE
| db: | CNVD | id: | CNVD-2010-1917 | date: | 2010-09-09T00:00:00 | 
SOURCES RELEASE DATE
| db: | CNVD | id: | CNVD-2010-1917 | date: | 2010-09-09T00:00:00 |