CVE-2022-24693
 
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)
Los dispositivos Baicells Nova436Q y Neutrino 430 con versiones de firmware hasta QRTB 2.7.8, presentan credenciales embebidas que son fácilmente detectadas, y pueden ser usadas por atacantes remotos para autenticarse por medio de ssh. (Las credenciales son almacenadas en el firmware, encriptadas por la función crypt)
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-02-09 CVE Reserved
- 2022-03-30 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-11-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://img.baicells.com/Upload/20210909/FILE/98d2752f-6e83-49b1-9dab-d291e9023db6.pdf | Release Notes |
URL | Date | SRC |
---|---|---|
https://github.com/lukejenkins/CVE-2022-24693 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://na.baicells.com/Service/Firmware | 2022-04-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Baicells Search vendor "Baicells" | Nova436q Firmware Search vendor "Baicells" for product "Nova436q Firmware" | <= qrtb_2.7.8 Search vendor "Baicells" for product "Nova436q Firmware" and version " <= qrtb_2.7.8" | - |
Affected
| in | Baicells Search vendor "Baicells" | Nova436q Search vendor "Baicells" for product "Nova436q" | - | - |
Safe
|
Baicells Search vendor "Baicells" | Neutrino 430 Firmware Search vendor "Baicells" for product "Neutrino 430 Firmware" | <= qrtb_2.7.8 Search vendor "Baicells" for product "Neutrino 430 Firmware" and version " <= qrtb_2.7.8" | - |
Affected
| in | Baicells Search vendor "Baicells" | Neutrino 430 Search vendor "Baicells" for product "Neutrino 430" | - | - |
Safe
|