vendor:
InfraPower PPS-02-S
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Hard-coded Credentials
798
CWE
Product Name: InfraPower PPS-02-S
Affected Version From: Q213V1 (Firmware: V2395S)
Affected Version To: Q216V3 (Firmware: IPD-02-FW-v03)
Patch Exists: YES
Related CWE: N/A
CPE: a:austin_huges_electronics_ltd:infrapower_pps-02-s
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 2.6.28 (armv5tel), lighttpd/1.4.30-devel-1321, PHP/5.3.9, SQLite/3.7.10
2016
InfraPower PPS-02-S Q213V1 Hard-coded Credentials Remote Root Access
InfraPower Manager PPS-02-S is a FREE built-in GUI of each IP dongle (IPD-02-S only) to remotely monitor the connected PDUs. Patented IP Dongle provides IP remote access to the PDUs by a true network IP address chain. InfraPower suffers from a use of hard-coded credentials. The IP dongle firmware ships with hard-coded accounts that can be used to gain full system access (root) using the telnet daemon on port 23.
Mitigation:
Upgrade to the latest version of the InfraPower Manager PPS-02-S (Q216V3) with Firmware IPD-02-FW-v03.