ID

VAR-201009-0309


TITLE

Edge-corE ES4649 Switch Password Security Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2010-1917

DESCRIPTION

Switches developed by Accton include 3Com, Dell, SMC, Foundry and EdgeCore, which have security vulnerabilities that allow malicious users to control devices. The problem is that the switch has a built-in \"__super\" user, and its password is generated based on the MAC address. The MAC address of the switch is obtained through ARP or SNMP. The management interface can be controlled through TELNET, SSH and HTTP.

Trust: 0.6

sources: CNVD: CNVD-2010-1917

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2010-1917

AFFECTED PRODUCTS

vendor:acctonmodel:edge-core es4649 switchscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2010-1917

EXTERNAL IDS

db:EXPLOIT-DBid:14875

Trust: 0.6

db:CNVDid:CNVD-2010-1917

Trust: 0.6

sources: CNVD: CNVD-2010-1917

REFERENCES

url:http://www.exploit-db.com/exploits/14875/http

Trust: 0.6

sources: CNVD: CNVD-2010-1917

SOURCES

db:CNVDid:CNVD-2010-1917

LAST UPDATE DATE

2022-05-17T02:09:16.577000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-1917date:2010-09-09T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2010-1917date:2010-09-09T00:00:00