International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped into a restricted shell, the attacker can trivially break out to achieve standard shell functionality.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Datacast Sfx2100_Firmware
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*
|
— | — |
|
Datacast Sfx2100
cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*
|
— | — |