CVE-2015-3959: Garrettcom Magnum 10k Firmware
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches has a hardcoded serial-console password for a privileged account, which might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation on which this account is enabled, and leveraging knowledge of this password.
Affected products
- Garrettcom Magnum 10k Firmware: up to and including 4.5.5
- Garrettcom Magnum 6k Firmware: up to and including 4.5.5
Published 2015-08-04. Last modified 2026-06-17.