Adtran - AOE Server Vulnerability Advisory
Cyber Security Threat Summary:
AOE servers that are not properly secured are susceptible to a security vulnerability that could potentially grant unauthorized access to the server via the AOE Server Admin user account. Such compromised servers are consequently vulnerable to ransomware attacks, posing a significant security risk.
Affected Products: The following products are within the scope of this vulnerability:
Suggested Correction(s):
To mitigate the risk associated with this vulnerability, Adtran recommends the following actions:
Immediate Disconnection: Adtran strongly advises the removal of any non-secured AOE servers. AOE requires the use of a properly configured firewall, VPN, or private network. Firewalls may allow traffic from known safe sources through specific firewall rules, for example a port forwarding rule allowing incoming traffic on a specific port from a specific IP address for OSS or Mosaic One communication. General or open access is not recommended. If you are uncertain about the server's connection status or security status, consider one of the following steps and contact Adtran Support (details below) for how to secure your server:
Adtran is asking organizations to take immediate action to address these recommendations to minimize the potential risks associated with this vulnerability.