Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for a bootloader password; however, this password is optional to meet different customers' needs
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2017/Feb/25 | third party advisory mailing list |
https://supportkb.riverbed.com/support/index?page=content&id=S30065 | mitigation vendor advisory |