Vulnerability Description
Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Eki-1321 Series Firmware | <= 1.96 |
| Advantech | Eki-1322 Series Firmware | <= 1.96 |
| Advantech | Eki-1321 | - |
| Advantech | Eki-1322 | - |
| Advantech | Eki-1361 Series Firmware | <= 1.17 |
| Advantech | Eki-1362 Series Firmware | <= 1.17 |
| Advantech | Eki-1361 | All versions |
| Advantech | Eki-1362 | All versions |
| Advantech | Eki-122X Series Firmware | <= 1.49 |
| Advantech | Eki-1221 | - |
| Advantech | Eki-1221D | - |
| Advantech | Eki-1222 | - |
| Advantech | Eki-1222D | - |
| Advantech | Eki-1224 | - |
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-309-01Third Party AdvisoryUS Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-309-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-6476?
CVE-2015-6476 is a vulnerability with a CVSS score of 10.0 (HIGH). Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for r...
How severe is CVE-2015-6476?
CVE-2015-6476 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6476?
Check the references section above for vendor advisories and patch information. Affected products include: Advantech Eki-1321 Series Firmware, Advantech Eki-1322 Series Firmware, Advantech Eki-1321, Advantech Eki-1322, Advantech Eki-1361 Series Firmware.