CVE-2012-4694

UnknownEPSS 1.10%

Last modified

CVE-2012-4694 is a vulnerability of currently unknown severity. Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.. EPSS estimates a 1.10% chance of exploitation in the next 30 days.

Description

Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.

Metrics

EPSS Probability
1.10%

61.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MoxaEdr G903 Firmware<= 2.2
MoxaEdr G903 Firmware1.0
MoxaEdr G903 Firmware2.0
MoxaEdr G903 Firmware2.1
MoxaEdr-G903All versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-4694?
Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
How severe is CVE-2012-4694?
Severity scoring for CVE-2012-4694 is pending analysis. The EPSS model estimates a 1.10% probability of exploitation in the next 30 days.
How do I fix CVE-2012-4694?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-4694?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST