CVE-2020-29382
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
29/11/2020
Last modified:
01/12/2020
Description
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. A hardcoded RSA private key (specific to V1600D, V1600G1, and V1600G2) is contained in the firmware images.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:vsolcn:v1600d_firmware:2.03.57:*:*:*:*:*:*:* | ||
| cpe:2.3:o:vsolcn:v1600d_firmware:2.03.69:*:*:*:*:*:*:* | ||
| cpe:2.3:h:vsolcn:v1600d:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:vsolcn:v1600g1_firmware:1.9.7:*:*:*:*:*:*:* | ||
| cpe:2.3:o:vsolcn:v1600g1_firmware:2.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:h:vsolcn:v1600g1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:vsolcn:v1600g2_firmware:1.1.4:*:*:*:*:*:*:* | ||
| cpe:2.3:h:vsolcn:v1600g2:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



