CVE-2020-29055
By default, the appliance can be managed remotely only with HTTP, telnet, and SNMP.
Does this matter?
Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. By default, the appliance can be managed remotely only with HTTP, telnet, and SNMP. It doesn't support SSL/TLS for HTTP or SSH. An attacker can intercept passwords sent in cleartext and conduct man-in-the-middle attacks on the management of the appliance.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- cdatatec/72408a firmware · cdatatec/9008a firmware · cdatatec/9016a firmware · cdatatec/92408a firmware · cdatatec/92416a firmware · cdatatec/9288 firmware · cdatatec/97016 firmware · cdatatec/97024p firmware · cdatatec/97028p firmware · cdatatec/97042p firmware · cdatatec/97084p firmware · cdatatec/97168p firmware · cdatatec/fd1002s firmware · cdatatec/fd1104 firmware · cdatatec/fd1104b firmware · cdatatec/fd1104s firmware · cdatatec/fd1104sn firmware · cdatatec/fd1108s firmware · cdatatec/fd1204s-r2 firmware · cdatatec/fd1204sn firmware · +8 more
- Source
- cve@mitre.org
References
- https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.htmlExploit, Third Party Advisory
- https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.