The vendor explicitly identifies these products as affected by this CVE.
- FBXi Firmware Version <= 9.3.4
- FBVi Firmware Version <= 9.3.4
- FBTi Firmware Version <= 9.3.4
- CBXi Firmware Version <= 9.3.4
- Summary
- Some information may be improperly disclosed through https access. This issue affects FLXEON<= 9.3.4
- Remediation
- - Stop and disconnect any FLXEON products that are exposed directly to the Internet, either via a direct ISP connection or via NAT port forwarding - Ensure that physical controls are in place, so no unauthorized personnel can access your devices, components, peripheral equipment, and networks - Ensure that all FLXEON products are upgraded to the latest firmware version (9.3.5 or above). Please find the latest version of FLXEON firmware on the respective product homepage - When remote access is required, only use secure methods. If a Virtual Private Network (VPN) is used, ensure that the chosen VPN is secure i.e. updated to the most current version available and configured for se-cure access.
