ID

VAR-201601-0675


TITLE

BalckEnergy SSH Backdoor

Trust: 0.2

sources: IVD: 73e4b3a4-1e6c-11e6-8415-000c29c12f8f

DESCRIPTION

The user's password is generated using a simpler algorithm , The attacker can obtain the highest authentication authority directly after analysis and cracking ( root ) Permissions

Trust: 0.2

sources: IVD: 73e4b3a4-1e6c-11e6-8415-000c29c12f8f

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 73e4b3a4-1e6c-11e6-8415-000c29c12f8f

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 73e4b3a4-1e6c-11e6-8415-000c29c12f8f
value: HIGH

Trust: 0.2

IVD: 73e4b3a4-1e6c-11e6-8415-000c29c12f8f
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 73e4b3a4-1e6c-11e6-8415-000c29c12f8f

TYPE

Weak backdoor password

Trust: 0.2

sources: IVD: 73e4b3a4-1e6c-11e6-8415-000c29c12f8f

EXTERNAL IDS

db:IVDid:73E4B3A4-1E6C-11E6-8415-000C29C12F8F

Trust: 0.2

sources: IVD: 73e4b3a4-1e6c-11e6-8415-000c29c12f8f

SOURCES

db:IVDid:73e4b3a4-1e6c-11e6-8415-000c29c12f8f

LAST UPDATE DATE

2022-05-04T09:17:57.487000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:73e4b3a4-1e6c-11e6-8415-000c29c12f8fdate:2016-01-28T00:00:00