Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
4.2.1-084 (custom)
affected
Description
In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's components to perform OS command executions.
Problem types
CWE-798 Use of Hard-coded Credentials
Product status
4.2.1-084 (custom)
Credits
Tomer Goldschmidt of Claroty Team82
References
www.cisa.gov/news-events/ics-advisories/icsa-25-126-01