CVE-2019-9975: High severity dasan networks h660rm vulnerability
Published Apr 11, 2019
·Updated
DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key.
Affected Software
4 affected components
All of the following
Dasannetworks H660rm Firmware=1.03-0022
Dasannetworks H660rm
Dasannetworks H660rm Firmware=1.03-0022
Dasannetworks H660rm
Event History
Apr 11, 2019
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9975?
CVE-2019-9975 is classified as a high severity vulnerability due to the use of a hard-coded encryption key.
2
How do I fix CVE-2019-9975?
To mitigate CVE-2019-9975, users should update the firmware of DASAN H660RM devices to a version that does not use a hard-coded encryption key.
3
What types of devices are affected by CVE-2019-9975?
CVE-2019-9975 specifically affects DASAN H660RM devices running firmware version 1.03-0022.
4
What are the implications of CVE-2019-9975?
CVE-2019-9975 allows unauthorized access to logs as the hard-coded key can be exploited to decrypt sensitive data.
5
Can CVE-2019-9975 be exploited remotely?
Yes, CVE-2019-9975 can potentially be exploited remotely if an attacker has access to the device's logs.