7.5
CVSSv2

CVE-2015-0936

Published: 01/06/2017 Updated: 17/06/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote malicious users to obtain SSH access by leveraging knowledge of the private key.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ceragon fibeair_ip-10_firmware -

Exploits

## # This module requires Metasploit: metasploitcom/download # Current source: githubcom/rapid7/metasploit-framework ## require 'msf/core' require 'net/ssh' class MetasploitModule < Msf::Exploit::Remote include Msf::Auxiliary::Report Rank = ExcellentRanking def initialize(info = {}) super(update_info(info, { ...
Ceragon FibeAir IP-10 suffers from an SSH private key exposure vulnerability ...
Ceragon FibeAir IP-10 versions 720 and below suffer from a hidden user backdoor vulnerability ...