CVE-2018-5399: The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running and is configured with a hard-coded credentials
The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running. The Dropbear server is configured with a hard-coded user name and password combination of root / amroot. The server is configured to use password only authentication not cryptographic keys, however the firmware image contains an RSA host-key for the server. An attacker can exploit this vulnerability to gain root access to the Angstrom Linux operating system and modify any binaries or configuration files in the firmware. Affected releases are Auto-Maskin DCU-210E RP-210E: Versions prior to 3.7 on ARMv7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5399?
CVE-2018-5399 is considered a critical vulnerability due to the presence of hard-coded credentials in the Dropbear SSH server.
How do I fix CVE-2018-5399?
To mitigate CVE-2018-5399, users should upgrade the Auto-Maskin DCU 210E firmware to a version that does not include this vulnerability.
What products are impacted by CVE-2018-5399?
CVE-2018-5399 affects the Auto-Maskin DCU 210E and RP 210E firmware versions prior to 3.7.
Is it safe to use the Auto-Maskin DCU 210E with CVE-2018-5399?
Using the Auto-Maskin DCU 210E with CVE-2018-5399 poses significant security risks due to the exposure of hard-coded credentials.
What is the attack vector for CVE-2018-5399?
The attack vector for CVE-2018-5399 is remote, as it allows unauthorized access via the SSH server listening on Port 22.