6.1
CVE-2012-4898
- EPSS 0.91%
- Veröffentlicht 18.12.2012 12:30:05
- Zuletzt bearbeitet 16.06.2026 23:45:52
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Tropos Wireless Mesh Routers Insufficient Entropy
Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tropos ≫ 1310 Distrubution Automation Mesh Router Version-
Tropos ≫ 1410 Mesh Router Version-
Tropos ≫ 1410 Wireless Mesh Router Version-
Tropos ≫ 3310 Indoor Mesh Router Version-
Tropos ≫ 3320 Indoor Mesh Router Version-
Tropos ≫ 4310 Mobile Mesh Router Version-
Tropos ≫ 6310 Mesh Router Version-
Tropos ≫ 6320 Mesh Router Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.91% | 0.553 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 4.9 | 7.8 |
AV:N/AC:H/Au:N/C:C/I:P/A:N
|
| ics-cert@hq.dhs.gov | 6.1 | 4.9 | 7.8 |
AV:N/AC:H/Au:N/C:C/I:P/A:N
|
http://www.us-cert.gov/control_systems/pdf/ICSA-12-297-01.pdf
https://www.cisa.gov/news-events/ics-advisories/icsa-12-297-01