The vendor explicitly identifies these products as affected by this CVE.
- FBXi Firmware Version <= 9.3.5
- FBVi Firmware Version <= 9.3.5
- FBTi Firmware Version <= 9.3.5
- CBXi Firmware Version <= 9.3.5
- Summary
- Credentials that are required for the functioning of the product cannot be stored in a HW supported secure storage as the product does not implement such a component.
- Remediation
- Follow Mitigating factors. - Stop and disconnect any FLXEON products that are exposed directly to the Internet, either via a direct ISP connection or via NAT port forwarding. - Ensure that physical controls are in place, so no unauthorized personnel can access your devices, components, peripheral equipment, and networks. - Ensure that all FLXEON products are upgraded to the latest firmware version. Please find the latest version of FLXEON firmware on the respective product homepage. - When remote access is required, only use secure methods. If a Virtual Private Network (VPN) is used, ensure that the chosen VPN is secure i.e. updated to the most current version available and configured for secure access.
