10
CVE-2013-0137
- EPSS 13.45%
- Veröffentlicht 30.06.2013 19:28:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 contains a known SSH private key, which makes it easier for remote attackers to obtain root access, and spoof alerts, via an SSH session.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Digital Alert Systems ≫ Dasdec Eas Version <= 2.0-1
Digital Alert Systems ≫ Dasdec Eas Version2.0-0
Monroe Electronics ≫ R189 One-net Eas Version <= 2.0-1
Monroe Electronics ≫ R189 One-net Eas Version2.0-0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 13.45% | 0.959 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
http://www.digitalalertsystems.com/pdf/130604-Monroe-Security-PR.pdf
http://www.kb.cert.org/vuls/id/662676
http://www.kb.cert.org/vuls/id/AAMN-98MU7H
http://www.kb.cert.org/vuls/id/AAMN-98MUK2
http://www.monroe-electronics.com/MONROE_ELECTRONICS_PDF/130604-Monroe-Security-PR.pdf
https://securityledger.com/2020/01/seven-years-later-scores-of-eas-systems-sit-un-patched-vulnerable/