SecureWise Product Security Action Recommendations

SecureWise Product Security Action Recommendations

Overview

 

We have released a security update to fix vulnerabilities in our products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

SecuwaySSL Version: U 2.0 Full Version
SecuwaySSL Version: U 1.0 Full Version

 

 

Resolved Vulnerabilities

 

Vulnerability in SecuWiz SecuwaySSL U 1.0/2.0 Root Password Exposure

 

 

Vulnerability Patches

Please follow the instructions on the Referenced Sites to perform the recommended security measures.

 

– set a blocking policy for the SSH access port of the SecuwaySSL device on the Internet network
* check the deny rule in “Device Security Policy” on the admin page
– apply the latest security patches by contacting SQWIZ or your maintenance provider
* if your product’s maintenance contract has expired, you can apply patches online through Securitywise
– Change the password of Root account (after patching)

 

 

References

 

[1] Security Advisory for SecureWiz Products
https://www.krcert.or.kr/kr/bbs/view.do?searchCnd=1&bbsId=B0000133&searchWrd=&menuNo=205020&pageIndex=1&categoryCode=&nttId=71847