CVE Vulnerabilities

CVE-2015-7923

Published: Jan 30, 2016 | Modified: Mar 07, 2016
CVSS 3.x
9
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Westermo WeOS before 4.19.0 uses the same SSL private key across different customers installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.

Affected Software

Name Vendor Start Version End Version
Weos Westermo 4.18.0 (including) 4.18.0 (including)

References