CVE-2019-17584 describes a critical vulnerability in Meinberg SyncBox/PTP/PTPv2 devices, where default, hardcoded SSH keys grant attackers root access. This affects all firmware versions up to v5.34o, v5.34s, v5.32*, or 5.34g. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating that an attacker with low privileges can achieve high impact across confidentiality, integrity, and availability over a network with high attack complexity. While the vulnerability is not listed in CISA's KEV catalog and has no known public exploits (Metasploit, Nuclei, ExploitDB), the vendor has released an update to address the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.34oCPE matchmatch criteria | cpe:2.3:o:meinbergglobal:syncbox\/ptpv2_firmware:*:*:*:*:*:*:*:* | ||
< 5.34sCPE matchmatch criteria | cpe:2.3:o:meinbergglobal:syncbox\/ptpv2_firmware:*:*:*:*:*:*:*:* | ||
< 5.32CPE matchmatch criteria | cpe:2.3:o:meinbergglobal:syncbox\/ptpv2_firmware:*:*:*:*:*:*:*:* | ||
< 5.34gCPE matchmatch criteria | cpe:2.3:o:meinbergglobal:syncbox\/ptpv2_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.