Vulnerability Description
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Seiko-Sol | Skybridge Mb-A200 Firmware | <= 01.00.04 |
| Seiko-Sol | Skybridge Mb-A200 | - |
Related Weaknesses (CWE)
References
- https://gist.github.com/Nwqda/0db1fc6cfa39d7f0592d44e18c40146eBroken Link
- https://www.seiko-sol.co.jp/products/skybridge/lineup/mb-a200/ProductVendor Advisory
- https://gist.github.com/Nwqda/0db1fc6cfa39d7f0592d44e18c40146eBroken Link
- https://www.seiko-sol.co.jp/products/skybridge/lineup/mb-a200/ProductVendor Advisory
FAQ
What is CVE-2022-36560?
CVE-2022-36560 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/...
How severe is CVE-2022-36560?
CVE-2022-36560 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-36560?
Check the references section above for vendor advisories and patch information. Affected products include: Seiko-Sol Skybridge Mb-A200 Firmware, Seiko-Sol Skybridge Mb-A200.