Vulnerability Description
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ciphertexts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ekahau | Real-Time Location System Controller | 6.0.5-final |
| Ekahau | Activator | 3 |
| Ekahau | B4 Staff Badge Tag Firmware | 1.4.52 |
| Ekahau | B4 Staff Badge Tag | 5.7 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/129585/Ekahau-Real-Time-Location-System-RC4
- http://www.modzero.ch/advisories/MZ-14-01-Ekahau-RTLS.txt
- http://www.securityfocus.com/archive/1/534241/100/0/threaded
- http://www.securityfocus.com/bid/71674
- http://packetstormsecurity.com/files/129585/Ekahau-Real-Time-Location-System-RC4
- http://www.modzero.ch/advisories/MZ-14-01-Ekahau-RTLS.txt
- http://www.securityfocus.com/archive/1/534241/100/0/threaded
- http://www.securityfocus.com/bid/71674
FAQ
What is CVE-2014-2716?
CVE-2014-2716 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to...
How severe is CVE-2014-2716?
CVE-2014-2716 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2716?
Check the references section above for vendor advisories and patch information. Affected products include: Ekahau Real-Time Location System Controller, Ekahau Activator, Ekahau B4 Staff Badge Tag Firmware, Ekahau B4 Staff Badge Tag.