this post was submitted on 28 Oct 2024
136 points (100.0% liked)

Cybersecurity

8283 readers
79 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
 

Static credentials with passwords written into a firewall's code. What could go wrong?

you are viewing a single comment's thread
view the rest of the comments
[–] jmcs@discuss.tchncs.de 13 points 10 months ago* (last edited 10 months ago) (18 children)

~~Right in the Security Advisory~~

allow an unauthenticated, local attacker to access an affected system using static credentials.

Edit: NVM, later it says

The second is using SSH, which is enabled by default on the management interface of the device.

[–] ryannathans@aussie.zone -2 points 10 months ago (4 children)

The management interface is only available with physical access

[–] jaybone@lemmy.world 6 points 10 months ago (3 children)

Nothing prevents you from putting this on a LAN that can be accessed from over the internet.

[–] ryannathans@aussie.zone 1 points 10 months ago

Nothing prevents you from making it remotely accessible with the password "password" either

load more comments (2 replies)
load more comments (2 replies)
load more comments (15 replies)