CVE-2020-29063 Information

Description

An issue was discovered on CDATA 72408A 9008A 9016A 92408A 92416A 9288 97016 97024P 97028P 97042P 97084P 97168P FD1002S FD1104 FD1104B FD1104S FD1104SN FD1108S FD1204S-R2 FD1204SN FD1204SN-R2 FD1208S-R2 FD1216S-R1 FD1608GS FD1608SN FD1616GS FD1616SN and FD8000 devices. A custom encryption algorithm is used to store encrypted passwords. This algorithm will XOR the password with the hardcoded j7a(LyZ98sSd5HfSgGjMj8;Ss;d)(&^@$a2s0i3g value.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

7.5

Share on: