Root access via hard-coded weak password
Published Apr 8, 2024 · Updated Aug 15, 2024
Hard-coded credentials in Atos OpenScape Desk Phone IP firmware 1.10.4.3 allow remote attackers on the local network to gain root access. The firmware stores the same weak md5crypt hash for the Unix root account in /etc/shadow, and offline guessing recovers the embedded password. The public advisory does not identify which network service accepts this account, but successful use grants root control of the phone.
Summary
What happened
Hard-coded credentials in Atos OpenScape Desk Phone IP firmware 1.10.4.3 allow remote attackers on the local network to gain root access. The firmware stores the same weak md5crypt hash for the Unix root account in /etc/shadow, and offline guessing recovers the embedded password. The public advisory does not identify which network service accepts this account, but successful use grants root control of the phone.
The record
- CVE
- CVE-2024-28066
- Published
- Apr 8, 2024
- Updated
- Aug 15, 2024
- Vendor
- Atos
- Product
- OpenScape Desk Phone IP 35G Firmware
- Classifications
- CWE-1391, CWE-259, T1078
- Attack vector
- adjacent
- Privileges
- unauthenticated
Timeline
How it unfolded
- Apr 8, 2024CVE publishedPublication date reported by the CVE source.
- Aug 15, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1.10.4.3 <=*
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- SYSS-2024-008 firmware-extraction proof of conceptfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo