7.6
CVE-2012-4687
- EPSS 1.42%
- Veröffentlicht 08.12.2012 15:55:00
- Zuletzt bearbeitet 16.06.2026 23:45:34
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Post Oak Bluetooth Traffic Systems Insufficient Entropy
Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof a device by predicting a key value.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Postoaktraffic ≫ Awam Bluetooth Reader Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.42% | 0.693 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
| ics-cert@hq.dhs.gov | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
CWE-331 Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
http://www.us-cert.gov/control_systems/pdf/ICSA-12-335-01.pdf
http://www.postoaktraffic.com/contact.aspx
https://www.cisa.gov/news-events/ics-advisories/icsa-12-335-01