Vulnerability CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012 or CVE-2016-8858

Issue:
Security scans are producing CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012 or CVE-2016-8858 as possible vulnerability.

Cause:
Reported as security issue in OpenSSH module.

Solution:
The product design is a closed system using data streams that are restricted to each user.

Only admin level users can access the unit directly outside of the data streams. With admin level access, the user will have full view of the unit by elevation and can download modifications to the unit configuration.

Future IOLAN firmware releases including OpenSSH 7.4 will clear the scan trigger (even though it does not apply in this product design).


Article ID:
637
Published:
1/21/2020 12:00:52 PM
Last Modified:
1/21/2020 12:06:51 PM
Keywords:
CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-8858, security, scan
Issue Type:
FAQ