CVE-2020-29054 - CVE House
Back to Database
Status published Critical CVE-2020-29054

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A,...

Vulnerability Description

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. Attackers can use "show system infor" to discover cleartext TELNET credentials.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-29054

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

72408a firmware, 9008a firmware, 9016a firmware, 92408a firmware, 92416a firmware, 9288 firmware, 97016 firmware, 97024p firmware, 97028p firmware, 97042p firmware, 97084p firmware, 97168p firmware, fd1002s firmware, fd1104 firmware, fd1104b firmware, fd1104s firmware, fd1104sn firmware, fd1108s firmware, fd1204s-r2 firmware, fd1204sn firmware, fd1204sn-r2 firmware, fd1208s-r2 firmware, fd1216s-r1 firmware, fd1608gs firmware, fd1608sn firmware, fd1616gs firmware, fd1616sn firmware, fd8000 firmware
Vulnerable Versions:
1.2.2, 2.4.03_000, 2.4.04_001, 2.4.05_000

Timeline

Official Publish: November 24th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.