Use of a broken or risky cryptographic algorithm in R6700 - #VU29043

 

Use of a broken or risky cryptographic algorithm in R6700 - #VU29043

Published: June 16, 2020


Vulnerability identifier: #VU29043
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-327
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system

The vulnerability exists due to the weak encryption of firmware update images within the "check_ra" functionality. An attacker on the local network can execute arbitrary code on the system.


Affected software

R6700

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins