Описание
Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, which makes it easier for remote attackers to obtain access by leveraging knowledge of a key from a product installation elsewhere.
Ссылки
- US Government Resource
- US Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 1.3 (включая)
Одновременно
cpe:2.3:o:moxa:oncell_gateway_firmware:*:*:*:*:*:*:*:*
Одно из
cpe:2.3:h:moxa:oncell_gateway_g3111:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:oncell_gateway_g3151:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:oncell_gateway_g3211:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:oncell_gateway_g3251:-:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00526
Низкий
7.1 High
CVSS2
Дефекты
CWE-310
Связанные уязвимости
github
больше 3 лет назад
Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, which makes it easier for remote attackers to obtain access by leveraging knowledge of a key from a product installation elsewhere.
EPSS
Процентиль: 66%
0.00526
Низкий
7.1 High
CVSS2
Дефекты
CWE-310