Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
Weaknesses in this category are related to errors in the management of cryptographic keys.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/131259/Ceragon-FibeAir-IP-10-SSH-Private-Key-Exposure.html | vdb entry third party advisory |
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&uact=8&ved=0ahUKEwjs47SGp47UAhVF5iYKHYGLDQkQFggoMAE&url=https%3A%2F%2Fwww.rapid7.com%2Fdb%2Fmodules%2Fexploit%2Flinux%2Fssh%2Fceragon_fibeair_known_privkey&usg=AFQjCNFZiZcWj47cpqPX-AbfpsW0DL4yYw | third party advisory exploit |
https://gist.github.com/todb-r7/5d86ecc8118f9eeecc15 | third party advisory |
http://packetstormsecurity.com/files/131260/Ceragon-FibeAir-IP-10-SSH-Private-Key-Exposure.html | exploit vdb entry third party advisory |
http://www.securityfocus.com/bid/73696 | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2015/Apr/3 | third party advisory mailing list |