10

CVE-2009-1473

The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not properly use RSA cryptography for a symmetric session-key negotiation, which makes it easier for remote attackers to (a) decrypt network traffic, or (b) conduct man-in-the-middle attacks, by repeating unspecified "client-side calculations."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AtenKh1516i Ip Kvm Switch Version1.0.063 Update- Editionjava_client
AtenKh1516i Ip Kvm Switch Version1.0.063 Update- Editionwindows_client
AtenKn9116 Ip Kvm Switch Version1.1.104 Update- Editionjava_client
AtenKn9116 Ip Kvm Switch Version1.1.104 Update- Editionwindows_client
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.94% 0.755
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C