CVE-2020-29054

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. Attackers can use "show system infor" to discover cleartext TELNET credentials.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:cdatatec:72408a_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:72408a_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:72408a_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:72408a_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:72408a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:cdatatec:9008a_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:9008a_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:9008a_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:9008a_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:9008a:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:cdatatec:9016a_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:9016a_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:9016a_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:9016a_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:9016a:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:cdatatec:92408a_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:92408a_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:92408a_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:92408a_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:92408a:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:cdatatec:92416a_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:92416a_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:92416a_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:92416a_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:92416a:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:cdatatec:9288_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:9288_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:9288_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:9288_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:9288:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:cdatatec:97016_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97016_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97016_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97016_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:97016:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
OR cpe:2.3:o:cdatatec:97024p_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97024p_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97024p_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97024p_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:97024p:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
OR cpe:2.3:o:cdatatec:97028p_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97028p_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97028p_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97028p_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:97028p:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:cdatatec:97042p_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97042p_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97042p_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97042p_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:97042p:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
OR cpe:2.3:o:cdatatec:97084p_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97084p_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97084p_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97084p_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:97084p:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
OR cpe:2.3:o:cdatatec:97168p_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97168p_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97168p_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:97168p_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:97168p:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1002s_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1002s_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1002s_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1002s_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1002s:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1104_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1104:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1104b_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104b_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104b_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104b_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1104b:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1104s_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104s_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104s_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104s_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1104s:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1104sn_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104sn_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104sn_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1104sn_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1104sn:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1108s_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1108s_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1108s_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1108s_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1108s:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1204s-r2_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1204s-r2_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1204s-r2_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1204s-r2_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1204s-r2:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1204sn_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1204sn_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1204sn_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1204sn_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1204sn:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1204sn-r2_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1204sn-r2_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1204sn-r2_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1204sn-r2_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1204sn-r2:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1208s-r2_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1208s-r2_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1208s-r2_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1208s-r2_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1208s-r2:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1216s-r1_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1216s-r1_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1216s-r1_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1216s-r1_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1216s-r1:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1608gs_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1608gs_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1608gs_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1608gs_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1608gs:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1608sn_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1608sn_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1608sn_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1608sn_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1608sn:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1616gs_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1616gs_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1616gs_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1616gs_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1616gs:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
OR cpe:2.3:o:cdatatec:fd1616sn_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1616sn_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1616sn_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd1616sn_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd1616sn:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
OR cpe:2.3:o:cdatatec:fd8000_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd8000_firmware:2.4.03_000:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd8000_firmware:2.4.04_001:*:*:*:*:*:*:*
cpe:2.3:o:cdatatec:fd8000_firmware:2.4.05_000:*:*:*:*:*:*:*
cpe:2.3:h:cdatatec:fd8000:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:23

Type Values Removed Values Added
References () https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html - Exploit, Third Party Advisory () https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html - Exploit, Third Party Advisory

Information

Published : 2020-11-24 21:15

Updated : 2024-11-21 05:23


NVD link : CVE-2020-29054

Mitre link : CVE-2020-29054

CVE.ORG link : CVE-2020-29054


JSON object : View

Products Affected

cdatatec

  • fd1208s-r2
  • 97042p_firmware
  • 97168p
  • 97016
  • fd1104s_firmware
  • fd1216s-r1
  • fd8000
  • 97016_firmware
  • 92416a_firmware
  • fd1204sn_firmware
  • 92416a
  • 97024p_firmware
  • fd1204sn-r2
  • 9016a_firmware
  • fd1608sn
  • 97168p_firmware
  • fd1108s_firmware
  • fd1616sn_firmware
  • fd8000_firmware
  • fd1002s
  • 72408a
  • 97028p_firmware
  • 9288_firmware
  • fd1216s-r1_firmware
  • fd1608sn_firmware
  • 97084p
  • 9008a_firmware
  • fd1002s_firmware
  • 9008a
  • 97024p
  • fd1204sn
  • fd1608gs_firmware
  • fd1616gs
  • fd1104sn_firmware
  • fd1204s-r2
  • fd1616sn
  • fd1208s-r2_firmware
  • fd1104s
  • fd1104b_firmware
  • 97028p
  • fd1104sn
  • 9288
  • 72408a_firmware
  • 92408a
  • fd1104_firmware
  • fd1108s
  • fd1204s-r2_firmware
  • 92408a_firmware
  • 9016a
  • fd1608gs
  • 97042p
  • 97084p_firmware
  • fd1204sn-r2_firmware
  • fd1104
  • fd1616gs_firmware
  • fd1104b
CWE
CWE-522

Insufficiently Protected Credentials