MEDIUM · 4.6

CVE-2005-2329

MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to acc...

Vulnerability Description

MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to access the consoles of other users.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Mrv CommunicationsIn Reach Lx 1000S3.5
Mrv CommunicationsIn Reach Lx 4000S3.5
Mrv CommunicationsIn Reach Lx 8000S3.5

References

FAQ

What is CVE-2005-2329?

CVE-2005-2329 is a vulnerability with a CVSS score of 4.6 (MEDIUM). MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to acc...

How severe is CVE-2005-2329?

CVE-2005-2329 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2329?

Check the references section above for vendor advisories and patch information. Affected products include: Mrv Communications In Reach Lx 1000S, Mrv Communications In Reach Lx 4000S, Mrv Communications In Reach Lx 8000S.