First published: Thu Apr 11 2019(Updated: )
DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dasannetworks H660rm Firmware | =1.03-0022 | |
Dasannetworks H660rm | ||
All of | ||
Dasannetworks H660rm Firmware | =1.03-0022 | |
Dasannetworks H660rm |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9975 is classified as a high severity vulnerability due to the use of a hard-coded encryption key.
To mitigate CVE-2019-9975, users should update the firmware of DASAN H660RM devices to a version that does not use a hard-coded encryption key.
CVE-2019-9975 specifically affects DASAN H660RM devices running firmware version 1.03-0022.
CVE-2019-9975 allows unauthorized access to logs as the hard-coded key can be exploited to decrypt sensitive data.
Yes, CVE-2019-9975 can potentially be exploited remotely if an attacker has access to the device's logs.