Описание
Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers to obtain sensitive information by decrypting a backup configuration file, as demonstrated by a password hash in the um_auth_account_password field.
Ссылки
- Third Party Advisory
- Broken Link
- PatchThird Party Advisory
- Third Party Advisory
- Broken Link
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:hitrontech:cve-30360_firmware:3.1.1.21:*:*:*:*:*:*:*
cpe:2.3:h:hitrontech:cve-30360:-:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05607
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-310
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers to obtain sensitive information by decrypting a backup configuration file, as demonstrated by a password hash in the um_auth_account_password field.
EPSS
Процентиль: 90%
0.05607
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-310