CVE-2019-8950: Critical severity dasan networks h665 firmware vulnerability
Published Feb 20, 2019
·Updated
The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET.
Affected Software
4 affected components
All of the following
Dasannetworks H665 Firmware=1.46p1-0028
Dasannetworks H665
Dasannetworks H665 Firmware=1.46p1-0028
Dasannetworks H665
Event History
Feb 20, 2019
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-8950?
CVE-2019-8950 is considered a high severity vulnerability due to the presence of a backdoor account that allows unauthorized access.
2
How do I fix CVE-2019-8950?
To fix CVE-2019-8950, update the firmware of DASAN H665 devices to a version that does not include the backdoor account.
3
What devices are affected by CVE-2019-8950?
CVE-2019-8950 affects DASAN H665 devices running firmware version 1.46p1-0028.
4
What impact does CVE-2019-8950 have on security?
CVE-2019-8950 allows an attacker to gain unauthorized access to the admin account via TELNET, compromising device security.
5
Is there a known exploit for CVE-2019-8950?
CVE-2019-8950 is known to be vulnerable to exploitation due to the accessible backdoor account in the affected firmware.