vendor:
Rugged Operating System (ROS®)
by:
jc
8,8
CVSS
HIGH
Backdoor Access
287
CWE
Product Name: Rugged Operating System (ROS®)
Affected Version From: All released versions
Affected Version To: All released versions
Patch Exists: YES
Related CWE: CVE-2012-1803
CPE: h:ruggedcom:rugged_operating_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
Undocumented Backdoor Access to RuggedCom Devices
An undocumented backdoor account exists within all released versions of RuggedCom's Rugged Operating System (ROS®). The username for the account, which cannot be disabled, is 'factory' and its password is dynamically generated based on the device's MAC address. Multiple attempts have been made in the past 12 months to have this backdoor removed and customers notified. An example exploit is provided in the text.
Mitigation:
Disable the backdoor account or update to the latest version of the Rugged Operating System (ROS®).