« Volver al listado

CVE-2016-10308

Estado: ModificadaCrítica (9.8)—

Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-10308",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-03-30T07:59:00.237",
  "references": [
    {
      "url": "http://blog.iancaling.com/post/145309944453",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/97243",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.iancaling.com/post/145309944453",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/97243",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it."
    },
    {
      "lang": "es",
      "value": "Siklu EtherHaul radios en versiones anteriores a 3.7.1 y 6.x en versiones anteriores a 6.9.0 tienen incorporada, una cuenta root oculta, con una contraseña inalterable que es la misma en todos los dispositivos. Esta cuenta es accesible a través de SSH y la interface web del dispositivo y concede el acceso al OS Linux incrustado en el dispositivo, permitiendo un control total sobre él."
    }
  ],
  "lastModified": "2026-06-17T00:39:27.187",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siklu:etherhaul_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E5FCA0E-EE0E-423C-9805-DC6F4E8416D1",
              "versionEndIncluding": "3.7.0"
            },
            {
              "criteria": "cpe:2.3:o:siklu:etherhaul_firmware:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C6BC2B9-5985-4DD5-93A1-5CD6603F4B21"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siklu:etherhaul-5500fd:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "129AECB7-8446-43D4-8D68-6B889DEB9E8A"
            },
            {
              "criteria": "cpe:2.3:h:siklu:etherhaul_500tx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "06C63B8C-013D-4C6B-9AE0-B93F9B48B7DB"
            },
            {
              "criteria": "cpe:2.3:h:siklu:etherhaul_60ghz_v-band_radio:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "677C7A13-EE9C-4423-A2CB-7A631B03AA32"
            },
            {
              "criteria": "cpe:2.3:h:siklu:etherhaul_70\\/80ghz_gigabit_radio:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B7B64120-E688-4F85-9425-D1F62AE9EB7A"
            },
            {
              "criteria": "cpe:2.3:h:siklu:etherhaul_70\\/80ghz_multi-gigabit_e-band_radio:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6CDAA518-3237-47A6-9C2E-DF1506262939"
            },
            {
              "criteria": "cpe:2.3:h:siklu:etherhaul_70ghz_e-band_radio:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A3970FA0-7CBD-484D-A580-CD4A74C63075"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}