Vulnerabilities > CVE-2011-0885 - Credentials Management vulnerability in SMC Networks Smcd3G-Ccr and Smcd3G-Ccr Firmware

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
smc-networks
CWE-255
exploit available

Summary

A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme for the mso account, which makes it easier for remote attackers to obtain administrative access via the (1) web interface or (2) TELNET interface.

Vulnerable Configurations

Part Description Count
Hardware
Smc_Networks
1
Application
Smc_Networks
2

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionComcast DOCSIS 3.0 Business Gateways Multiple Vulnerabilities. CVE-2011-0885,CVE-2011-0886,CVE-2011-0887. Remote exploit for hardware platform
fileexploits/hardware/remote/16123.txt
idEDB-ID:16123
last seen2016-02-01
modified2011-02-06
platformhardware
port
published2011-02-06
reporterTrustwave's SpiderLabs
sourcehttps://www.exploit-db.com/download/16123/
titleComcast DOCSIS 3.0 Business Gateways Multiple Vulnerabilities
typeremote

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/98180/TWSL2011-002.txt
idPACKETSTORM:98180
last seen2016-12-05
published2011-02-05
reporterTrustwave
sourcehttps://packetstormsecurity.com/files/98180/Comcast-DOCSIS-3.0-Business-Gateways-XSRF-Session-Management.html
titleComcast DOCSIS 3.0 Business Gateways XSRF / Session Management

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:70676
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-70676
titleComcast DOCSIS 3.0 Business Gateways Multiple Vulnerabilities