Vulnerability Description
Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof a device by predicting a key value.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Postoaktraffic | Awam Bluetooth Reader | - |
Related Weaknesses (CWE)
References
- http://www.postoaktraffic.com/contact.aspx
- https://www.cisa.gov/news-events/ics-advisories/icsa-12-335-01
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-335-01.pdfUS Government Resource
FAQ
What is CVE-2012-4687?
CVE-2012-4687 is a vulnerability with a CVSS score of 7.6 (HIGH). Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof a device by predicting a key ...
How severe is CVE-2012-4687?
CVE-2012-4687 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4687?
Check the references section above for vendor advisories and patch information. Affected products include: Postoaktraffic Awam Bluetooth Reader.