Описание
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES Key that can be used for packet decryption (obtaining cleartext credentials) by an attacker who has access to a wired port.
Ссылки
- MitigationVendor Advisory
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.0 (включая) до 5.8.6.9 (исключая)Версия от 5.9.0 (включая) до 5.9.1.3 (исключая)
Одно из
cpe:2.3:o:extremenetworks:extremewireless_wing:*:*:*:*:*:*:*:*
cpe:2.3:o:extremenetworks:extremewireless_wing:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00136
Низкий
7.5 High
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-798
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES Key that can be used for packet decryption (obtaining cleartext credentials) by an attacker who has access to a wired port.
EPSS
Процентиль: 34%
0.00136
Низкий
7.5 High
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-798