CVE-2019-9976: High severity dasan networks h660rm vulnerability
Published Apr 11, 2019
·Updated
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users.
Affected Software
4 affected components
Dasannetworks H660rm Firmware=1.03-0022
Dasannetworks H660rm
All of the following
Dasannetworks H660rm Firmware=1.03-0022
Dasannetworks H660rm
Event History
Apr 11, 2019
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9976?
CVE-2019-9976 has a medium severity rating due to its potential to expose sensitive user credentials.
2
How do I fix CVE-2019-9976?
To fix CVE-2019-9976, upgrade the firmware of your DASAN H660RM devices to a version higher than 1.03-0022.
3
What devices are affected by CVE-2019-9976?
CVE-2019-9976 affects DASAN H660RM devices running firmware version 1.03-0022.
4
What type of data is exposed in CVE-2019-9976?
CVE-2019-9976 exposes POST data including credentials to the administration web interface.
5
Who can exploit CVE-2019-9976?
Any logged-in user on the DASAN H660RM device can potentially exploit CVE-2019-9976 to access sensitive information.