First published: Thu Jun 16 2005(Updated: )
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Enterasys Vertical Horizon-2402s | =2.05.09.07 | |
Enterasys Vertical Horizon-2402s | =2.05.00 | |
Enterasys Vertical Horizon-2402s | =2.05.08.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2026 is considered a high severity vulnerability due to the potential for remote privilege escalation.
To fix CVE-2005-2026, upgrade the firmware of the Enterasys Vertical Horizon VH-2402S to version 2.05.05.09 or later.
CVE-2005-2026 affects the Enterasys Vertical Horizon VH-2402S models running versions prior to 2.05.05.09.
Yes, CVE-2005-2026 can be exploited remotely by attackers to gain unauthorized access due to hard-coded credentials.
If CVE-2005-2026 is not addressed, malicious users may exploit the hard-coded debugging account to gain privileged access to the device.