CVE-2018-12336: Infoleak
Published Jun 17, 2018
·Updated
Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access.
Affected Software
2 affected components
ECOS Secure Boot Stick Firmware=5.6.5
ECOS Secure Boot Stick
Event History
Jun 17, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12336?
CVE-2018-12336 is classified as a high-severity vulnerability due to its potential for unauthorized remote access.
2
How do I fix CVE-2018-12336?
To mitigate CVE-2018-12336, update the firmware of the ECOS Secure Boot Stick to a version that does not include the documented backdoor.
3
What does CVE-2018-12336 allow an attacker to do?
CVE-2018-12336 allows an attacker to gain remote root SSH access, potentially extracting confidential information from the device.
4
Which software versions are affected by CVE-2018-12336?
CVE-2018-12336 affects the ECOS Secure Boot Stick firmware version 5.6.5.
5
Is there a known public exploit for CVE-2018-12336?
As of now, there are no publicly available exploits specifically associated with CVE-2018-12336.