CVE-2016-1984: Critical severity harman amx firmware vulnerability
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2015-8362.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1984?
CVE-2016-1984 is considered a high severity vulnerability due to the presence of a hardcoded password that allows unauthorized access.
How do I fix CVE-2016-1984?
To fix CVE-2016-1984, update the Harman AMX devices to a version beyond 1.3.100, as the hardcoded password issue is resolved in subsequent updates.
What devices are affected by CVE-2016-1984?
CVE-2016-1984 affects Harman AMX devices running firmware versions 1.2.322 and 1.3.100.
What type of access can be gained by exploiting CVE-2016-1984?
Exploiting CVE-2016-1984 allows remote attackers to gain unauthorized access via SSH or HTTP sessions.
Is CVE-2016-1984 a local or remote vulnerability?
CVE-2016-1984 is a remote vulnerability, enabling attackers to exploit it from outside the network.