CVE-2012-4577
 
Severity Score
10.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Linux firmware image on (1) Korenix Jetport 5600 series serial-device servers and (2) ORing Industrial DIN-Rail serial-device servers has a hardcoded password of "password" for the root account, which allows remote attackers to obtain administrative access via an SSH session.
La imagen del (firmware) de Linux en (1) en la serie de servidores (serial-device) Korenix Jetport 5600 y (2) en la serie de servidores (serial-device) ORing Industrial DIN-Rail tiene una contraseña codificada para la cuenta de (root) que permite a atacantes remotos obtener acceso con nivel administrativo a través de una sesión SSH.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-08-21 CVE Reserved
- 2012-08-21 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-12-263-02 | X_refsource_misc | |
http://ics-cert.us-cert.gov/advisories/ICSA-12-297-02 | X_refsource_misc | |
http://www.digitalbond.com/2012/06/13/korenix-and-oring-insecurity | X_refsource_misc | |
http://www.securityfocus.com/bid/55196 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/77992 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Korenix Search vendor "Korenix" | Jetport Search vendor "Korenix" for product "Jetport" | 5601 Search vendor "Korenix" for product "Jetport" and version "5601" | - |
Affected
| ||||||
Korenix Search vendor "Korenix" | Jetport Search vendor "Korenix" for product "Jetport" | 5601f Search vendor "Korenix" for product "Jetport" and version "5601f" | - |
Affected
| ||||||
Korenix Search vendor "Korenix" | Jetport Search vendor "Korenix" for product "Jetport" | 5604 Search vendor "Korenix" for product "Jetport" and version "5604" | - |
Affected
| ||||||
Korenix Search vendor "Korenix" | Jetport Search vendor "Korenix" for product "Jetport" | 5604i Search vendor "Korenix" for product "Jetport" and version "5604i" | - |
Affected
|