Release date:
Updated on:
Affected Systems:
Korenix Jetport 5600
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55196
Cve id: CVE-2012-4577
JetPort series is an intelligent RS-232 or RS-422/RS-485 serial port to Ethernet device networking server.
The Korenix Jetport 5600 series products have the vulnerability of Remote Authentication Bypass, the Linux firmware image on Korenix Jetport 5600 series server and ORing Industrial DIN-Rail series server has a hard-coded "password" for the root account, which is session over SSH, remote attackers can obtain administrator access permissions.
<* Source: Reid wihtman
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Korenix
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.korenix.com.cn/