Vulnerability Description
Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moxa | Edr G903 Firmware | <= 2.2 |
| Moxa | Edr-G903 | - |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-042-01.pdfUS Government Resource
- http://www.moxa.com/support/download.aspx?type=support&id=492
- http://ics-cert.us-cert.gov/pdf/ICSA-13-042-01.pdfUS Government Resource
- http://www.moxa.com/support/download.aspx?type=support&id=492
FAQ
What is CVE-2012-4694?
CVE-2012-4694 is a vulnerability with a CVSS score of 7.6 (HIGH). Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device o...
How severe is CVE-2012-4694?
CVE-2012-4694 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4694?
Check the references section above for vendor advisories and patch information. Affected products include: Moxa Edr G903 Firmware, Moxa Edr-G903.