CVE-2005-2189: Medium severity Lantronix SecureLinx vulnerability
Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2189?
CVE-2005-2189 is considered a high severity vulnerability as it allows remote attackers to access sensitive information.
How can I fix CVE-2005-2189?
The fix for CVE-2005-2189 involves updating the firmware of the Lantronix SecureLinx console server to the latest version that addresses this vulnerability.
Which versions of Lantronix SecureLinx are affected by CVE-2005-2189?
CVE-2005-2189 affects Lantronix SecureLinx versions 2.0 and 3.0.
What type of information can be accessed due to CVE-2005-2189?
Due to CVE-2005-2189, remote attackers can obtain sensitive information such as SSH private keys.
How does CVE-2005-2189 occur?
CVE-2005-2189 occurs because the Lantronix SecureLinx console server stores the /etc/ssh directory under the web document root with insufficient access control.