SecureWise Product Security Action Recommendations
Overview
We have released a security update to fix vulnerabilities in our products. Users of affected products are advised to update to the latest version.
Affected Products
SecuwaySSL Version: U 2.0 Full Version
SecuwaySSL Version: U 1.0 Full Version
Resolved Vulnerabilities
Vulnerability in SecuWiz SecuwaySSL U 1.0/2.0 Root Password Exposure
Vulnerability Patches
Please follow the instructions on the Referenced Sites to perform the recommended security measures.
– set a blocking policy for the SSH access port of the SecuwaySSL device on the Internet network
* check the deny rule in “Device Security Policy” on the admin page
– apply the latest security patches by contacting SQWIZ or your maintenance provider
* if your product’s maintenance contract has expired, you can apply patches online through Securitywise
– Change the password of Root account (after patching)
References
[1] Security Advisory for SecureWiz Products
https://www.krcert.or.kr/kr/bbs/view.do?searchCnd=1&bbsId=B0000133&searchWrd=&menuNo=205020&pageIndex=1&categoryCode=&nttId=71847