10
CVSSv2

CVE-2009-3710

Published: 16/10/2009 Updated: 19/10/2009
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote malicious users to gain privileges via port 8022.

Vulnerable Product Search on Vulmon Subscribe to Product

riorey rios 4.7.0

riorey rios 4.6.6

Exploits

Severity: High (Full root access to the device) Date: 07 October 2009 Versions Affected: RIOS 466 , 470 possibly others Discovered on: 25 July 2009 Vendor URL: wwwrioreycom Author: Marek Kroemeke Overview: Riorey DDoS mitigation appliences (wwwrioreycom) are vulnerable to taking a full control over affected devices via a hardcoded userna ...