CVE-2022-32985

libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
nexansgigaswitch_641_desk_v5_sfp-vi_firmware
𝑥
< 6.02n
nexansgigaswitch_641_desk_v5_sfp-vi_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_642_desk_v5_sfp-2vi_firmware
𝑥
< 6.02n
nexansgigaswitch_642_desk_v5_sfp-2vi_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_2tp_sfp-vi_54vdc_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_2tp_sfp-vi_54vdc_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_sfp-2vi_230vac_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_sfp-2vi_230vac_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_tp_sfp-2vi_54vdc_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_tp_sfp-2vi_54vdc_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_tp_sfp-2vi_54vdc_ind_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_tp_sfp-2vi_54vdc_med_firmware
7.0 ≤
𝑥
< 7.02
nexansgigaswitch_v5_tp_sfp-vi_230vac_firmware
𝑥
< 6.02n
nexansgigaswitch_v5_tp_sfp-vi_230vac_firmware
7.0 ≤
𝑥
< 7.02
𝑥
= Vulnerable software versions