7.6
CVE-2012-4694
- EPSS 1.1%
- Veröffentlicht 15.02.2013 12:09:27
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moxa ≫ Edr G903 Firmware Version <= 2.2
Moxa ≫ Edr G903 Firmware Version1.0
Moxa ≫ Edr G903 Firmware Version2.0
Moxa ≫ Edr G903 Firmware Version2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.1% | 0.614 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
http://ics-cert.us-cert.gov/pdf/ICSA-13-042-01.pdf
http://www.moxa.com/support/download.aspx?type=support&id=492