ID

VAR-201704-1423


CVE

CVE-2017-7576


TITLE

DragonWave Horizon Vulnerabilities related to the use of hard-coded credentials

Trust: 0.8

sources: JVNDB: JVNDB-2017-002992

DESCRIPTION

DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8. DragonWave Horizon Contains a vulnerability in the use of hard-coded credentials.Information is obtained, information is altered, and service operation is disrupted (DoS) An attack may be carried out. DragonWave Horizon is a carrier-grade point-to-point packet microwave system developed by DragonWave Corporation in Canada. The system provides functions such as transmission of broadband voice, video and data. A security vulnerability exists in DragonWave Horizon version 1.01.03 due to the device's use of hard-coded login credentials. An attacker could exploit this vulnerability to gain access to the device

Trust: 1.71

sources: NVD: CVE-2017-7576 // JVNDB: JVNDB-2017-002992 // VULHUB: VHN-115779

AFFECTED PRODUCTS

vendor:dragonwavemodel:horizon wireless radioscope:eqversion:1.01.03

Trust: 1.4

vendor:dragonwavexmodel:horizon wireless radioscope:eqversion:1.01.03

Trust: 1.0

sources: JVNDB: JVNDB-2017-002992 // CNNVD: CNNVD-201704-271 // NVD: CVE-2017-7576

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-7576
value: CRITICAL

Trust: 1.0

NVD: CVE-2017-7576
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201704-271
value: CRITICAL

Trust: 0.6

VULHUB: VHN-115779
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-7576
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-115779
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-7576
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2017-7576
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-115779 // JVNDB: JVNDB-2017-002992 // CNNVD: CNNVD-201704-271 // NVD: CVE-2017-7576

PROBLEMTYPE DATA

problemtype:CWE-798

Trust: 1.9

sources: VULHUB: VHN-115779 // JVNDB: JVNDB-2017-002992 // NVD: CVE-2017-7576

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201704-271

TYPE

trust management problem

Trust: 0.6

sources: CNNVD: CNNVD-201704-271

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-002992

PATCH

title:Top Pageurl:http://www.dragonwaveinc.com/

Trust: 0.8

title:DragonWave Horizon Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=69077

Trust: 0.6

sources: JVNDB: JVNDB-2017-002992 // CNNVD: CNNVD-201704-271

EXTERNAL IDS

db:NVDid:CVE-2017-7576

Trust: 2.5

db:JVNDBid:JVNDB-2017-002992

Trust: 0.8

db:CNNVDid:CNNVD-201704-271

Trust: 0.7

db:VULHUBid:VHN-115779

Trust: 0.1

sources: VULHUB: VHN-115779 // JVNDB: JVNDB-2017-002992 // CNNVD: CNNVD-201704-271 // NVD: CVE-2017-7576

REFERENCES

url:http://blog.iancaling.com/post/159276197313/

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-7576

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-7576

Trust: 0.8

url:http://blog.iancaling.com/post/159276197313/dragonwave-horizon-hard-coded-credentials

Trust: 0.8

sources: VULHUB: VHN-115779 // JVNDB: JVNDB-2017-002992 // CNNVD: CNNVD-201704-271 // NVD: CVE-2017-7576

SOURCES

db:VULHUBid:VHN-115779
db:JVNDBid:JVNDB-2017-002992
db:CNNVDid:CNNVD-201704-271
db:NVDid:CVE-2017-7576

LAST UPDATE DATE

2025-04-20T23:25:03.414000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-115779date:2017-04-12T00:00:00
db:JVNDBid:JVNDB-2017-002992date:2017-05-10T00:00:00
db:CNNVDid:CNNVD-201704-271date:2021-09-14T00:00:00
db:NVDid:CVE-2017-7576date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-115779date:2017-04-06T00:00:00
db:JVNDBid:JVNDB-2017-002992date:2017-05-10T00:00:00
db:CNNVDid:CNNVD-201704-271date:2017-04-11T00:00:00
db:NVDid:CVE-2017-7576date:2017-04-06T22:59:00.170