Planet Technology FGSW-2402RS Switch 后门密码重置漏洞

Planet Technology FGSW-2402RS Switch 后门密码重置漏洞

漏洞ID 1197646 漏洞类型 设计错误
发布时间 2005-10-14 更新时间 2005-10-20
图片[1]-Planet Technology FGSW-2402RS Switch 后门密码重置漏洞-安全小百科CVE编号 CVE-2005-3196
图片[2]-Planet Technology FGSW-2402RS Switch 后门密码重置漏洞-安全小百科CNNVD-ID CNNVD-200510-085
漏洞平台 N/A CVSS评分 4.6
|漏洞来源
https://cxsecurity.com/issue/WLB-2005100013
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200510-085
|漏洞详情
PlanetTechnologyCorpFGSW2402RSswitch是一款24口交换机PlanetTechnologyCorpFGSW2402RSswitchwithfirmware1.2带有默认密码,使得可物理访问设备的串行端口的攻击者可以获得特权。
|漏洞EXP
Hello all,

Today i discovered a pseudo backdoor [thru a default password] while trying to
reset the password on a Planet Technology Corp FGSW2402RS switch.

Allthough i dont consider this to be a real problem since the only access seems
to be thru the serial port, i would like to share this with the community since
it isnt documented *anywhere* and Planet Technology Corp doesnt even reply to
emails asking for support on their products.

So...we start with a common ASCII analisys of the firmware [revision 1.2]:
root@leonardo-root ~/planet# strings FGSW-2402RS_ISP_1.2.txt
...
admin
[^_^]
ISPMODE
...
root@leonardo-root ~/planet#

Admin is the obvious login and ISPMODE is the password used for uploading a new
firmware to the equipment.

If we connect to the equipment and send admin as the login and "[^_^]" as the
password we get the same login prompt again (as if the password had failed) and
the password has now been reset to "".

Best regards,
+-------------------------
| Lus Miguel Silva
| Security Consultant
| Centro de Informtica Correia Arajo
| Faculdade de Engenharia da
| Universidade do Porto
|参考资料

来源:BUGTRAQ
名称:20051006PlanetTechnologyCorpFGSW2402RSswitchdefaultpassword/
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112861552020302&w;=2
来源:BID
名称:15014
链接:http://www.securityfocus.com/bid/15014
来源:SREASON
名称:53
链接:http://securityreason.com/securityalert/53

相关推荐: Cisco外出访问控制列表绕过漏洞

Cisco外出访问控制列表绕过漏洞 漏洞ID 1205053 漏洞类型 设计错误 发布时间 2001-12-06 更新时间 2005-05-02 CVE编号 CVE-2001-0866 CNNVD-ID CNNVD-200112-030 漏洞平台 N/A CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享