DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Dropbear vulnerability
- oliverm2
- Topic Author
- Offline
- New Member
Less
More
- Posts: 7
- Thank yous received: 0
01 Jun 2017 19:40 #89027
by oliverm2
Dropbear vulnerability was created by oliverm2
Hi all
We have a Draytek 3900 running fw 1.3.0. Our vulnerability scanner has picked up an issue with the implementation of SSH. Is there a way to report this to Draytek HQ and have them look at patching?
For now we've disabled SSH, but really such a thing should be resolved for those people who need SSH support.
Here's the vulnerability report.
Dropbear SSH Multiple Vulnerabilities
Risk:Serious
Application:ssh
Port:22
Protocol:tcp
ScriptID:106381
Vulnerability Detection Result: Installed version: 0.49 Fixed version: 2016.74
Summary: Dropbear SSH is prone to multiple vulnerabilities.
CVSS Base Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
Impact: An authenticated attacker may run arbitrary code.
Solution: Update to 2016.74 or later.
Vulnerability Detection Method: Checks the version.
Affected Software/OS: Dropbear SSH 2016.73 and prior.
We have a Draytek 3900 running fw 1.3.0. Our vulnerability scanner has picked up an issue with the implementation of SSH. Is there a way to report this to Draytek HQ and have them look at patching?
For now we've disabled SSH, but really such a thing should be resolved for those people who need SSH support.
Here's the vulnerability report.
Dropbear SSH Multiple Vulnerabilities
Risk:Serious
Application:ssh
Port:22
Protocol:tcp
ScriptID:106381
Vulnerability Detection Result: Installed version: 0.49 Fixed version: 2016.74
Summary: Dropbear SSH is prone to multiple vulnerabilities.
CVSS Base Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
Impact: An authenticated attacker may run arbitrary code.
Solution: Update to 2016.74 or later.
Vulnerability Detection Method: Checks the version.
Affected Software/OS: Dropbear SSH 2016.73 and prior.
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank yous received: 0
02 Jun 2017 02:07 #89028
by hornbyp
Replied by hornbyp on topic Re: Dropbear vulnerability
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek