6.1
CVE-2012-4898
- EPSS 0.15%
- Veröffentlicht 18.12.2012 12:30:05
- Zuletzt bearbeitet 09.07.2025 17:15:29
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tropos ≫ 1310 Distrubution Automation Mesh Router Version-
Tropos ≫ 1410 Mesh Router Version-
Tropos ≫ 1410 Wireless Mesh Router Version-
Tropos ≫ 3310 Indoor Mesh Router Version-
Tropos ≫ 3320 Indoor Mesh Router Version-
Tropos ≫ 4310 Mobile Mesh Router Version-
Tropos ≫ 6310 Mesh Router Version-
Tropos ≫ 6320 Mesh Router Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.358 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 4.9 | 7.8 |
AV:N/AC:H/Au:N/C:C/I:P/A:N
|
| ics-cert@hq.dhs.gov | 6.1 | 4.9 | 7.8 |
AV:N/AC:H/Au:N/C:C/I:P/A:N
|