The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Receiver insecurely stores the hardcoded root password hash. The password itself is highly insecure and susceptible to offline dictionary attacks using the rockyou.txt wordlist. Because direct root SSH login is disabled, an attacker must first obtain low-privileged access to the system (e.g., via other vulnerabilities) to be able to log in as the root user. The password is hardcoded and so allows for an actor with local access on effected versions to escalate to root
The file /root/anaconda-ks.cfg contains a hardcoded root user password hash. This password is simple enough to be cracked offline using popular wordlists such as rockyou.txt. Since direct root login via SSH is disabled, an attacker must first obtain access with low privileges (e.g., through other vulnerabilities), and then use the recovered password to escalate privileges to the root account.
An attacker with local, unprivileged access to the system can take full control of the device as root, obtaining unlimited access to its resources and configuration, as well as to connected systems (high impact on confidentiality and integrity in system context).
Apply patches available from the manufacturer according to references. As interim measures, it is recommended to change the default root password to a strong, unique password and restrict local access to the device to trusted users only. The file /root/anaconda-ks.cfg should be secured or deleted.
International Datacasting Corporation (IDC) SFX2100 SuperFlex Satellite Receiver — Datacast SFX2100 firmware (versions indicated in manufacturer references)
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDatacast Sfx2100
HWDatacastall versionsDatacast Sfx2100 Firmware
OSDatacastall versions
Related vulnerabilities
IDC SFX2100: błędne uprawnienia katalogu umożliwiają privilege escalation
Hardcoded hasło w urządzeniu IDC SFX2100 – nieautoryzowany dostęp SSH
Command Injection w narzędziu Traceroute interfejsu IDC SFX2100
Command injection w narzędziu diagnostycznym Ping urządzenia IDC SFX2100
RCE jako root przez SNMP w odbiorniku IDC SFX Series SuperFlex