Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-17704

Опубликовано: 31 дек. 2017
Источник: nvd
CVSS3: 7.4
CVSS2: 5.8
EPSS Низкий

Описание

A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the fixed IV, leading to replay attacks of entire messages. There is no authentication of messages beyond the use of the fixed AES key, so message forgery is also possible.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:swhouse:istar_ultra_firmware:*:*:*:*:*:*:*:*
Версия до 6.5.2.20569 (включая)
cpe:2.3:h:swhouse:istar_ultra:-:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00155
Низкий

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 7.4
github
больше 3 лет назад

A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the fixed IV, leading to replay attacks of entire messages. There is no authentication of messages beyond the use of the fixed AES key, so message forgery is also possible.

EPSS

Процентиль: 36%
0.00155
Низкий

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-330