Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35hv-m5vp-r3wp

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.

Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.

EPSS

Процентиль: 47%
0.00237
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
nvd
около 10 лет назад

Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.

EPSS

Процентиль: 47%
0.00237
Низкий

9 Critical

CVSS3