Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hq59-x6xq-jvxw

Опубликовано: 05 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded

SSL certificate and private key. An attacker with access to these items

could potentially perform a man in the middle attack between the

ACEManager client and ACEManager server.

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded

SSL certificate and private key. An attacker with access to these items

could potentially perform a man in the middle attack between the

ACEManager client and ACEManager server.

EPSS

Процентиль: 1%
0.00008
Низкий

8.1 High

CVSS3

Дефекты

CWE-321
CWE-798

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 лет назад

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.

CVSS3: 8.1
fstec
больше 2 лет назад

Уязвимость операционной системы ALEOS беспроводных маршрутизаторов Sierra Wireless MP70, RV50x, RV55, LX40, LX60 ES450, GX450, позволяющая нарушителю реализовать атаку типа «человек посередине»

EPSS

Процентиль: 1%
0.00008
Низкий

8.1 High

CVSS3

Дефекты

CWE-321
CWE-798