CVE-2022-32985

l

ibnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_641_desk_v5_sfp-vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_641_desk_v5_sfp-vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_641_desk_v5_sfp-vi:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_642_desk_v5_sfp-2vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_642_desk_v5_sfp-2vi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_642_desk_v5_sfp-2vi:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_2tp_sfp-vi_54vdc:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_sfp-2vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_sfp-2vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_sfp-2vi_230vac:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_ind:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-2vi_54vdc_med:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
OR cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nexans:gigaswitch_v5_tp_sfp-vi_230vac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nexans:gigaswitch_v5_tp_sfp-vi_230vac:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:07

Type Values Removed Values Added
References () https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/ - Exploit, Third Party Advisory () https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/ - Exploit, Third Party Advisory
References () https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html - Vendor Advisory () https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html - Vendor Advisory