CVE-2012-4898
Published Dec 18, 2012
Last updated 12 years ago
Overview
- Description
- Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.1
- Impact score
- 7.8
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:C/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-310
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:tropos:mesh_os:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E8693B2-5D42-46A1-9994-42E5BADCAB75", "versionEndIncluding": "7.9.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:tropos:1310_distrubution_automation_mesh_router:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7852E70-8D02-482E-95FB-2E0CA77E17B4" }, { "criteria": "cpe:2.3:h:tropos:1410_mesh_router:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E27A596C-9AB4-47FB-8CC1-A442AE2B166B" }, { "criteria": "cpe:2.3:h:tropos:1410_wireless_mesh_router:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A03DF812-5697-4216-B34A-68F862258BB4" }, { "criteria": "cpe:2.3:h:tropos:3310_indoor_mesh_router:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB430981-1D88-4C92-BC7E-A6AFA1525A76" }, { "criteria": "cpe:2.3:h:tropos:3320_indoor_mesh_router:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B9E51A6-A559-4113-A7C6-EE3C7DF1B5EE" }, { "criteria": "cpe:2.3:h:tropos:4310_mobile_mesh_router:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "668A0BBA-9F67-4E63-A2CE-7A114B42E58F" }, { "criteria": "cpe:2.3:h:tropos:6310_mesh_router:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E564CC3-C509-428D-AEB4-8F100ECFF0B3" }, { "criteria": "cpe:2.3:h:tropos:6320_mesh_router:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0FA11508-E41A-431A-9386-7D8A95C0D8D6" } ], "operator": "OR" } ], "operator": "AND" } ]