First published: Sun Nov 29 2020(Updated: )
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. A hardcoded RSA private key (specific to V1600D, V1600G1, and V1600G2) is contained in the firmware images.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vsolcn V1600d | =2.03.57 | |
Vsolcn V1600d | =2.03.69 | |
Vsolcn V1600d4l | ||
Vsolcn V1600g1 | =1.9.7 | |
Vsolcn V1600g1 | =2.0.7 | |
Vsolcn V1600g1 Firmware | ||
Vsolcn V1600g2 | =1.1.4 | |
Vsolcn V1600g2 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-29382.
V-SOL V1600D (V2.03.57 and V2.03.69), V1600G1 (V1.9.7 and V2.0.7), and V1600G2 (V1.1.4) OLT devices are affected.
The severity of CVE-2020-29382 is high with a CVSS score of 7.8.
To fix the vulnerability, update the firmware of the affected devices to a version that does not contain the hardcoded RSA private key.
You can find more information about CVE-2020-29382 at the following link: [https://seclists.org/fulldisclosure/2020/Jul/14](https://seclists.org/fulldisclosure/2020/Jul/14).