Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfw8-4p7f-cjjh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

A vulnerability has been identified in SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

A vulnerability has been identified in SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

EPSS

Процентиль: 38%
0.0017
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-321
CWE-798

Связанные уязвимости

CVSS3: 5.9
nvd
около 5 лет назад

A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

CVSS3: 5.9
fstec
около 5 лет назад

Уязвимость функции reset промышленных коммутаторов SCALANCE X-200, SCALANCE X-200IRT, SCALANCE X-300, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 38%
0.0017
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-321
CWE-798