7.8

CVE-2014-2362

OleumTech WIO Use of Cryptographically Weak Pseudo-Random Number Generator

OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.58% 0.723
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 8.6 7.8
AV:N/AC:M/Au:N/C:C/I:P/A:N
ics-cert@hq.dhs.gov 7.8 8.6 7.8
AV:N/AC:M/Au:N/C:C/I:P/A:N
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/68797
http://www.securityfocus.com/bid/68800
http://support.oleumtech.com/
https://www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a