First published: Sun Nov 29 2020(Updated: )
An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. A hardcoded RSA private key (specific to V1600D4L and V1600D-MINI) is contained in the firmware images.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vsolcn V1600d4l | =1.01.49 | |
Vsolcn V1600d4l Firmware | ||
Vsolcn V1600d-mini Firmware | =1.01.48 | |
Vsolcn V1600d-mini Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29383 is classified as a critical severity vulnerability due to the presence of a hardcoded RSA private key.
To mitigate CVE-2020-29383, update the firmware of V-SOL V1600D4L and V1600D-MINI devices to the latest version that removes the hardcoded key.
CVE-2020-29383 affects V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices.
The risks associated with CVE-2020-29383 include unauthorized access and control over the affected devices due to the availability of the hardcoded key.
Yes, a patch addressing CVE-2020-29383 is available through firmware updates for the affected devices.