Horizon Alert
Summary of the vulnerability and why it matters
This advisory details a vulnerability where sensitive credentials, including default ones, are stored in plaintext within configuration files. These files can be accessed through the command line or exported via TFTP, which can be initiated without authentication using SNMP. This could allow an attacker with administrator privileges to obtain these credentials.
- Plaintext credentials stored in accessible files.
- Information disclosure impacts sensitive access controls.
- Confirm relevance and exposure for your environment.
Attack Path
How an attacker could exploit the issue
An attacker with low privileges could access sensitive credentials stored in plaintext within a configuration file. This file can be accessed via the command line interface or exported using TFTP, which can be initiated through an unauthenticated SNMP request. This exposure of sensitive information could then be leveraged for further malicious activities.
- Requires low privileges to access.
- Triggered by exporting configuration via TFTP.
- Exposes sensitive credentials for misuse.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could expose sensitive information like usernames and passwords stored in device configuration files. When administrator rights are available, these credentials can be accessed via the CLI or exported through a TFTP transfer initiated from the web interface. A TFTP transfer can also be triggered using SNMP without requiring authentication, when supported by the advisory.
- Usernames and passwords may be exposed.
- Via unauthenticated TFTP or authenticated CLI/web export.
- Unauthorized access to the system could occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts systems where usernames and passwords, including default credentials, are stored in plaintext within configuration files, accessible via CLI or TFTP through SNMP without authentication. Identifying the scope and criticality of affected systems is the immediate priority, followed by confirming accountable owners and planning remediation.
- Identify and confirm asset ownership.
- Verify system reachability and criticality.
- Plan remediation based on risk.