Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jw3-xmj9-qvcw

Опубликовано: 15 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.

The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.

EPSS

Процентиль: 71%
0.00692
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1279
CWE-908

Связанные уязвимости

CVSS3: 6.4
nvd
около 2 лет назад

The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.

EPSS

Процентиль: 71%
0.00692
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1279
CWE-908