7.5

CVE-2024-41594

An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DraytekVigor2620 Firmware
   DraytekVigor2620 Version-
DraytekVigor2915 Firmware Version < 4.4.5.3
   DraytekVigor2915 Version-
DraytekVigor2866 Firmware Version < 4.4.5.2
   DraytekVigor2866 Version-
DraytekVigor2766 Firmware Version < 4.4.5.3
   DraytekVigor2766 Version-
DraytekVigor2865 Firmware Version < 4.4.5.2
   DraytekVigor2865 Version-
DraytekVigor2765 Firmware Version < 4.4.5.3
   DraytekVigor2765 Version-
DraytekVigor2763 Firmware Version < 4.4.5.3
   DraytekVigor2763 Version-
DraytekVigor2135 Firmware Version < 4.4.5.3
   DraytekVigor2135 Version-
DraytekVigor166 Firmware Version < 4.2.7
   DraytekVigor166 Version-
DraytekVigor1000b Firmware Version < 4.3.2.8
   DraytekVigor1000b Version-
DraytekVigor1000b Firmware Version >= 4.4.0.0 < 4.4.3.1
   DraytekVigor1000b Version-
DraytekVigor165 Firmware Version < 4.2.7
   DraytekVigor165 Version-
DraytekVigor3910 Firmware Version < 4.3.2.8
   DraytekVigor3910 Version-
DraytekVigor3910 Firmware Version >= 4.4.0.0 < 4.4.3.1
   DraytekVigor3910 Version-
DraytekVigor2962 Firmware Version < 4.3.2.8
   DraytekVigor2962 Version-
DraytekVigor2962 Firmware Version >= 4.4.0.0 < 4.4.3.1
   DraytekVigor2962 Version-
DraytekVigor3912 Firmware Version < 4.3.6.1
   DraytekVigor3912 Version-
DraytekVigor2133 Firmware
   DraytekVigor2133 Version-
DraytekVigor2762 Firmware
   DraytekVigor2762 Version-
DraytekVigor2832 Firmware
   DraytekVigor2832 Version-
DraytekVigor2860 Firmware
   DraytekVigor2860 Version-
DraytekVigor2862 Firmware
   DraytekVigor2862 Version-
DraytekVigor2925 Firmware
   DraytekVigor2925 Version-
DraytekVigor2926 Firmware
   DraytekVigor2926 Version-
DraytekVigor2952 Firmware
   DraytekVigor2952 Version-
DraytekVigor3220 Firmware
   DraytekVigor3220 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.18
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

https://www.forescout.com/resources/draybreak-draytek-research/
Third Party Advisory
Mitigation
Technical Description
https://www.forescout.com/resources/draytek14-vulnerabilities
Broken Link