7.8
CVE-2014-2362
- EPSS 1.05%
- Veröffentlicht 24.07.2014 14:55:07
- Zuletzt bearbeitet 06.10.2025 18:15:47
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oleumtech ≫ Wio Dh2 Wireless Gateway Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.05% | 0.768 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 8.6 | 7.8 |
AV:N/AC:M/Au:N/C:C/I:P/A:N
|
| ics-cert@hq.dhs.gov | 7.8 | 8.6 | 7.8 |
AV:N/AC:M/Au:N/C:C/I:P/A:N
|
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.