International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Datacast Sfx2100_Firmware
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*
|
— | — |
|
Datacast Sfx2100
cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*
|
— | — |