[HIGH] SSH password authentication enabled on 10.1.11.21 (undocumented media server) #37
Labels
No labels
area:documentation
area:infrastructure
area:network
area:security
priority:critical
priority:high
priority:low
priority:medium
status:blocked
type:bug
type:deployment
type:enhancement
type:investigation
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
reinitialized.net/infrastructure#37
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description
SSH on host
10.1.11.21accepts password-based authentication. This is the only host on the 10.1.11.0/24 subnet that accepts password logins.Finding Details
Comparison with other hosts
Risk
Password authentication is vulnerable to brute-force attacks. Combined with 8 exposed web services (see #36), a compromised SSH session could provide full control of the media stack.
Recommendations
References