CVE-2022-32985

libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_641_desk_v5_sfp-vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_641_desk_v5_sfp-vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_641_desk_v5_sfp-vi:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_642_desk_v5_sfp-2vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_642_desk_v5_sfp-2vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_642_desk_v5_sfp-2vi:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_sfp-2vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_sfp-2vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_sfp-2vi_230vac:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-vi_230vac:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:07

Type Values Removed Values Added
References () https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/ - Exploit, Third Party Advisory () https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/ - Exploit, Third Party Advisory
References () https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html - Vendor Advisory () https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html - Vendor Advisory

25 Jul 2022, 21:16

Type Values Removed Values Added
CWE CWE-798
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-vi_230vac:-:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc:-:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_sfp-2vi_230vac:-:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_641_desk_v5_sfp-vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc:-:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_sfp-2vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_642_desk_v5_sfp-2vi:-:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_641_desk_v5_sfp-vi:-:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_642_desk_v5_sfp-2vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc:-:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
References (MISC) https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html - (MISC) https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html - Vendor Advisory
References (MISC) https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/ - (MISC) https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/ - Exploit, Third Party Advisory

17 Jul 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-17 23:15

Updated : 2024-11-21 07:07


NVD link : CVE-2022-32985

Mitre link : CVE-2022-32985

CVE.ORG link : CVE-2022-32985


JSON object : View

Products Affected

nexans

  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind
  • gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware
  • gigaswitch_v5_2tp_sfp-vi_54vdc_firmware
  • gigaswitch_641_desk_v5_sfp-vi
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware
  • gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med
  • gigaswitch_v5_tp_sfp-2vi_54vdc_ind
  • gigaswitch_v5_sfp-2vi_230vac
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc
  • gigaswitch_v5_tp_sfp-vi_230vac
  • gigaswitch_v5_tp_sfp-vi_230vac_firmware
  • gigaswitch_642_desk_v5_sfp-2vi_firmware
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware
  • gigaswitch_642_desk_v5_sfp-2vi
  • gigaswitch_v5_sfp-2vi_230vac_firmware
  • gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware
  • gigaswitch_v5_2tp_sfp-vi_54vdc
  • gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc
  • gigaswitch_v5_tp_sfp-2vi_54vdc_med
  • gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware
  • gigaswitch_641_desk_v5_sfp-vi_firmware
  • gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc
  • gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware
  • gigaswitch_v5_tp_sfp-2vi_54vdc_firmware
  • gigaswitch_v5_tp_sfp-2vi_54vdc
CWE
CWE-798

Use of Hard-coded Credentials