CVE-2022-32985

libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_641_desk_v5_sfp-vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_641_desk_v5_sfp-vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_641_desk_v5_sfp-vi:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_642_desk_v5_sfp-2vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_642_desk_v5_sfp-2vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_642_desk_v5_sfp-2vi:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_sfp-2vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_sfp-2vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_sfp-2vi_230vac:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-vi_230vac:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-07-17 23:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-32985

Mitre link : CVE-2022-32985

CVE.ORG link : CVE-2022-32985


JSON object : View

Products Affected

nexans

  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med
  • gigaswitch_v5_2tp_sfp-vi_54vdc
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware
  • gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware
  • gigaswitch_641_desk_v5_sfp-vi_firmware
  • gigaswitch_642_desk_v5_sfp-2vi_firmware
  • gigaswitch_v5_tp_sfp-2vi_54vdc_firmware
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware
  • gigaswitch_v5_tp_sfp-2vi_54vdc
  • gigaswitch_v5_tp_sfp-vi_230vac_firmware
  • gigaswitch_v5_tp_sfp-2vi_54vdc_med
  • gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware
  • gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc
  • gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware
  • gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware
  • gigaswitch_641_desk_v5_sfp-vi
  • gigaswitch_v5_sfp-2vi_230vac
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc
  • gigaswitch_v5_tp_sfp-2vi_54vdc_ind
  • gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc
  • gigaswitch_v5_sfp-2vi_230vac_firmware
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind
  • gigaswitch_v5_2tp_sfp-vi_54vdc_firmware
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware
  • gigaswitch_v5_tp_sfp-vi_230vac
  • gigaswitch_642_desk_v5_sfp-2vi
CWE
CWE-798

Use of Hard-coded Credentials