CVE-2019-16638: High severity ruijie eg-2000se firmware vulnerability
Published Jul 16, 2024
·Updated
An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects EG-2000SE EGRGOS 11.1(1)B1.
Affected Software
2 affected components
All of the following
Ruijie Eg-2000se Firmware=11.1\(1\)b1
Ruijie EG-2000SE
Event History
Jul 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16638?
CVE-2019-16638 is considered a high severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2019-16638?
To fix CVE-2019-16638, update the firmware of the Ruijie EG-2000SE gateway to a version that addresses this vulnerability.
3
What kind of attack is possible with CVE-2019-16638?
CVE-2019-16638 allows an attacker to dump cleartext stored passwords from the device's configuration file.
4
Which devices are affected by CVE-2019-16638?
CVE-2019-16638 affects the Ruijie EG-2000SE gateway running firmware version 11.1(1)B1.
5
Is user data compromised due to CVE-2019-16638?
Yes, user data can be compromised as cleartext passwords can be accessed if the vulnerability is exploited.