Описание
An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, allowing manipulation of transmitted data if the attacker can interact with the network traffic.
Ссылки
- Vendor Advisory
- US Government Resource
- Not Applicable
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.4.1 (исключая)
Одновременно
cpe:2.3:o:sick:lms1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:lms1000:-:*:*:*:*:*:*:*
Конфигурация 2Версия до 2.4.1 (исключая)
Одновременно
cpe:2.3:o:sick:mrs1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:mrs1000:-:*:*:*:*:*:*:*
EPSS
Процентиль: 10%
0.002
Низкий
6.5 Medium
CVSS3
8.1 High
CVSS3
Дефекты
CWE-327
Связанные уязвимости
CVSS3: 6.5
github
4 месяца назад
An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, allowing manipulation of transmitted data if the attacker can interact with the network traffic.
EPSS
Процентиль: 10%
0.002
Низкий
6.5 Medium
CVSS3
8.1 High
CVSS3
Дефекты
CWE-327