CVE-2015-0936 details a critical vulnerability in Ceragon FibeAir IP-10 devices, including various firmware versions and models like IP-10C, IP-10E, and IP-10G. This flaw stems from a default SSH public key present in the authorized_keys file for the 'mateidu' user. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows unauthenticated remote attackers to gain full SSH access to affected devices by leveraging knowledge of the corresponding private key, leading to complete compromise of confidentiality, integrity, and availability. While not on the CISA KEV catalog, a Metasploit module exists for exploitation, indicating readily available exploit code. Despite its high severity and ease of exploitation, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:ceragon:fibeair_ip-10_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.