Vulnerabilities > CVE-2015-3959 - Unspecified vulnerability in Garrettcom Magnum 10K Firmware and Magnum 6K Firmware
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches has a hardcoded serial-console password for a privileged account, which might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation on which this account is enabled, and leveraging knowledge of this password.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 |
References
- http://www.garrettcom.com/techsupport/MNS6K_R456_Release_Notes.pdf
- http://www.garrettcom.com/techsupport/MNS6K_R456_Release_Notes.pdf
- http://www.securityfocus.com/bid/75235
- http://www.securityfocus.com/bid/75235
- https://ics-cert.us-cert.gov/advisories/ICSA-15-167-01
- https://ics-cert.us-cert.gov/advisories/ICSA-15-167-01