CVE-2019-12776
Published Jun 7, 2019
Last updated 5 years ago
Overview
- Description
- An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's authorized_keys file, enabling anyone with the associated private key to gain remote root access to all affected products.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-798
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:enttec:datagate_mk2_firmware:70044:05032019-482:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B9A37C2-12DA-4B4F-ADA2-0AF9B8DB6AF7" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:enttec:datagate_mk2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "253A65CA-28AE-489B-B187-9C75E3D3E7EA" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:enttec:storm_24_firmware:70044:05032019-482:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CDAA74C7-1191-4E53-B4CB-24677F741044" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:enttec:storm_24:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C7068E69-8504-451B-B413-8B681AE41878" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:enttec:pixelator_firmware:70044:05032019-482:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00EBFAEB-AE67-4DBB-A427-CBCFAC24F8BF" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:enttec:pixelator:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D0C61125-DEE1-4ED3-ACC7-B0E9A0F0D993" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:enttec:e-streamer_mk2_firmware:70044:05032019-482:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AF62A27-2CD4-4E26-90C0-CBE5806FB568" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:enttec:e-streamer_mk2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F01D05A7-1D5B-4D27-AF4F-99A5B772D8B8" } ], "operator": "OR" } ], "operator": "AND" } ]