Description
GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism. Attackers can bypass login controls to access administrative functions and sensitive switch configuration without valid credentials.
Problem types
CWE-798 Use of Hard-coded Credentials
Product status
Any version
Any version
4.7.7 (semver)
References
assets.belden.com/...MNS-6K-10K-GarrettCom-BSECV-2017-08.pdf
www.vulncheck.com/...hentication-bypass-via-hardcoded-string