Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded keys and log in to such a device through SSH.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/93607 | vdb entry third party advisory |
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161017-01-storage-en | vendor advisory |