Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59rw-g46v-6c42

Опубликовано: 27 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

EPSS

Процентиль: 42%
0.00199
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-259
CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

EPSS

Процентиль: 42%
0.00199
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-259
CWE-798