CVE-2015-3959

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/08/2015
Last modified:
12/04/2025

Description

The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches has a hardcoded serial-console password for a privileged account, which might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation on which this account is enabled, and leveraging knowledge of this password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:garrettcom:magnum_10k_firmware:*:*:*:*:*:*:*:* 4.5.5 (including)
cpe:2.3:o:garrettcom:magnum_6k_firmware:*:*:*:*:*:*:*:* 4.5.5 (including)