Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v68j-53vw-j6rw

Опубликовано: 11 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an attacker to guess or decrypt the password from the cyphertext.

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an attacker to guess or decrypt the password from the cyphertext.

EPSS

Процентиль: 14%
0.00045
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 7.5
nvd
12 месяцев назад

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an attacker to guess or decrypt the password from the cyphertext.

CVSS3: 7.5
fstec
12 месяцев назад

Уязвимость микропрограммного обеспечения контроллеров APOGEE PXC, TALON TC, связанная с недостаточно стойким шифрованием данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 14%
0.00045
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-326