Unsecure Network Configuration in Kura Software by Eclipse
CVE-2017-7649
9.8CRITICAL
What is CVE-2017-7649?
The Kura software, prior to version 2.1.0, is susceptible to serious misconfigurations that allow unauthorized access to the device's control systems. By leaving the Equinox console port (5002) open and vulnerable to unencrypted Telnet connections, attackers can gain root access without requiring valid credentials. Additionally, the IPv6 firewall configuration is restricted, leaving devices in auto-configuration mode, which may attract malicious router advertisements. This combination of vulnerabilities can enable an attacker to exploit the system fully, allowing them to execute commands and compromise the device.
Affected Version(s)
Eclipse Kura Installer < 2.1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved