CVE-2022-47036

Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in newer hardware, which would typically be used with firmware 2.1.1 or later.
Configurations

No configuration.

History

21 Nov 2024, 07:31

Type Values Removed Values Added
References () https://semaja2.net/2023/06/11/siklu-tg-auth-bypass.html - () https://semaja2.net/2023/06/11/siklu-tg-auth-bypass.html -

27 Aug 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-284
Summary
  • (es) Los dispositivos Siklu TG Terragraph anteriores a aproximadamente 2.1.1 tienen una contraseña de root codificada que se ha revelado mediante un ataque de fuerza bruta en un hash MD5. Un administrador puede utilizarlo para "iniciar sesión de depuración". NOTA: la vulnerabilidad no se soluciona con el firmware 2.1.1; en cambio, se soluciona en hardware más nuevo, que normalmente se usaría con el firmware 2.1.1 o posterior.

18 Mar 2024, 04:15

Type Values Removed Values Added
Summary (en) Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, its is fixed in newer hardware, which would typically bs used with firmware 2.1.1 or later. (en) Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in newer hardware, which would typically be used with firmware 2.1.1 or later.

18 Mar 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 03:15

Updated : 2024-11-21 07:31


NVD link : CVE-2022-47036

Mitre link : CVE-2022-47036

CVE.ORG link : CVE-2022-47036


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control