CVE-2022-32967: Realtek RTL8111EP-CG/RTL8111FP-CG - Use of Hard-coded Credentials
RTL8111EP-CG/RTL8111FP-CG DASH function has hard-coded password. An unauthenticated physical attacker can use the hard-coded default password during system reboot triggered by other user, to acquire partial system information such as serial number and server information.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for RTL8111EP-CG/RTL8111FP-CG DASH function with hard-coded password?
The vulnerability ID is CVE-2022-32967.
What is the severity rating of CVE-2022-32967?
CVE-2022-32967 has a severity rating of 2.1 (low).
What is the impact of RTL8111EP-CG/RTL8111FP-CG DASH function vulnerability?
The vulnerability allows an unauthenticated physical attacker to acquire partial system information such as serial number and server information.
Which software versions are affected by the RTL8111EP-CG/RTL8111FP-CG DASH function vulnerability?
The affected software versions are Realtek Rtl8111ep-cg Firmware up to and including 3.0.0.2019090, and Realtek Rtl8111fp-cg Firmware up to and including 3.0.0.2019090.
How can the RTL8111EP-CG/RTL8111FP-CG DASH function vulnerability be fixed?
To fix the vulnerability, Realtek Rtl8111ep-cg Firmware and Realtek Rtl8111fp-cg Firmware should be updated to versions higher than 3.0.0.2019090.