First published: Tue Mar 05 2019(Updated: )
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.
Credit: vulnreport@tenable.com vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia I-240w-q Gpon Ont | =3fe54567bozj19 | |
Nokia I-240w-q Gpon Ont Firmware | ||
All of | ||
Nokia I-240w-q Gpon Ont | =3fe54567bozj19 | |
Nokia I-240w-q Gpon Ont Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3918 has a high severity rating due to the presence of hard coded credentials.
To fix CVE-2019-3918, update the firmware of the Alcatel Lucent I-240W-Q GPON ONT to a version without hard coded credentials.
CVE-2019-3918 affects the Alcatel Lucent I-240W-Q GPON ONT running firmware version 3FE54567BOZJ19.
CVE-2019-3918 allows unauthorized access to the Telnet and SSH interfaces, which can lead to further exploitation.
There is no known workaround for CVE-2019-3918; upgrading the firmware is the recommended approach.