Executive brief
FiberHome Fengine S5800 switches are susceptible to a denial-of-service attack that can lock administrators out of the device. By rapidly attempting to connect to the switch's management interface, an attacker can exhaust available connection slots. This prevents legitimate users from logging in via SSH or Telnet to manage the network, requiring a physical restart of the hardware to restore access.
Technical details
A resource consumption vulnerability (CWE-400) exists in the SSH service of FiberHome Fengine S5800 switches. An unauthenticated remote attacker can use automated tools to initiate rapid SSH connection attempts. This activity triggers an increase in the SSH login timeout, causing each connection attempt to occupy a session slot for an extended period. Once all available slots are exhausted, the device refuses further SSH and Telnet connections from legitimate administrators. Recovery requires a hard reboot of the device.
Affected products
- FiberHome Fengine S5800 firmware V210R240
- FiberHome Fengine S5800-28T-S
- FiberHome Fengine S5800-28T-S-PE
- FiberHome Fengine 28F-S
- FiberHome Fengine 52F-S
- FiberHome Fengine 52T-S
Timeline
- 2017-01-23: disclosed
- 2017-01-23: advisory