libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
History
21 Nov 2024, 07:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/ - Exploit, Third Party Advisory | |
References | () https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html - Vendor Advisory |
25 Jul 2022, 21:16
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-798 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-vi_230vac:-:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc:-:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_sfp-2vi_230vac:-:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_641_desk_v5_sfp-vi_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc:-:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_sfp-2vi_230vac_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_642_desk_v5_sfp-2vi:-:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-vi_230vac_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_641_desk_v5_sfp-vi:-:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_642_desk_v5_sfp-2vi_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:* cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc:-:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:* |
|
References | (MISC) https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html - Vendor Advisory | |
References | (MISC) https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/ - Exploit, Third Party Advisory |
17 Jul 2022, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-07-17 23:15
Updated : 2024-11-21 07:07
NVD link : CVE-2022-32985
Mitre link : CVE-2022-32985
CVE.ORG link : CVE-2022-32985
JSON object : View
Products Affected
nexans
- gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind
- gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware
- gigaswitch_v5_2tp_sfp-vi_54vdc_firmware
- gigaswitch_641_desk_v5_sfp-vi
- gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware
- gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware
- gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med
- gigaswitch_v5_tp_sfp-2vi_54vdc_ind
- gigaswitch_v5_sfp-2vi_230vac
- gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc
- gigaswitch_v5_tp_sfp-vi_230vac
- gigaswitch_v5_tp_sfp-vi_230vac_firmware
- gigaswitch_642_desk_v5_sfp-2vi_firmware
- gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware
- gigaswitch_642_desk_v5_sfp-2vi
- gigaswitch_v5_sfp-2vi_230vac_firmware
- gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware
- gigaswitch_v5_2tp_sfp-vi_54vdc
- gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc
- gigaswitch_v5_tp_sfp-2vi_54vdc_med
- gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware
- gigaswitch_641_desk_v5_sfp-vi_firmware
- gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc
- gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware
- gigaswitch_v5_tp_sfp-2vi_54vdc_firmware
- gigaswitch_v5_tp_sfp-2vi_54vdc
CWE
CWE-798
Use of Hard-coded Credentials