Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-5544

Опубликовано: 23 янв. 2017
Источник: nvd
CVSS3: 5.9
CVSS2: 7.1
EPSS Низкий

Описание

An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger an increase in the SSH login timeout (each of the login attempts will occupy a connection slot for a longer time). Once this occurs, legitimate login attempts via SSH/telnet will be refused, resulting in a denial of service; you must restart the device.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:fiberhome:fengine_s5800_firmware:v210r240:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:fiberhome:fengine_28f-s:-:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:fengine_52f-s:-:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:fengine_52t-s:-:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:fengine_s5800-28t-s:-:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:fengine_s5800-28t-s-pe:-:*:*:*:*:*:*:*

EPSS

Процентиль: 8%
0.00031
Низкий

5.9 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.9
github
больше 3 лет назад

An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger an increase in the SSH login timeout (each of the login attempts will occupy a connection slot for a longer time). Once this occurs, legitimate login attempts via SSH/telnet will be refused, resulting in a denial of service; you must restart the device.

EPSS

Процентиль: 8%
0.00031
Низкий

5.9 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-400