Realtek RTL8111EP-CG/RTL8111FP-CG - Use of Hard-coded Credentials
CVE-2022-32967

2.1LOW

Key Information:

Vendor

Realtek

Vendor
CVE Published:
29 November 2022

What is CVE-2022-32967?

RTL8111EP-CG/RTL8111FP-CG DASH function has hard-coded password. An unauthenticated physical attacker can use the hard-coded default password during system reboot triggered by other user, to acquire partial system information such as serial number and server information.

Affected Version(s)

RTL8111EP-CG <= 3.0.0.2019090

RTL8111EP-CG 5.0.10

RTL8111FP-CG <= 3.0.0.2019090

References

CVSS V3.1

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.