OpenELEC and RasPlex devices have a hardcoded password for the root account, which makes it easier for remote attackers to obtain access via an SSH session.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://github.com/RasPlex/RasPlex/issues/453 | |
http://www.kb.cert.org/vuls/id/544527 | third party advisory us government resource |