CVE-2012-4702
360 Systems Maxx, Image Server Maxx, and Image Server 2000 have a hardcoded password for the root account, which makes it easier for remote attackers to execute arbitrary code, or modify video content or scheduling, via an SSH session.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
360 Systems Maxx, Image Server Maxx, and Image Server 2000 have a hardcoded password for the root account, which makes it easier for remote attackers to execute arbitrary code, or modify video content or scheduling, via an SSH session.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.80% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- 360systems/image server 2000 · 360systems/image server maxx · 360systems/maxx
- Source
- ics-cert@hq.dhs.gov
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-038-01A.pdfUS Government Resource
- http://ics-cert.us-cert.gov/pdf/ICSA-13-038-01A.pdfUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.