CVE-2012-4898

UnknownEPSS 0.91%

Last modified

CVE-2012-4898 is a vulnerability of currently unknown severity. Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.. EPSS estimates a 0.91% chance of exploitation in the next 30 days.

Description

Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.

Metrics

EPSS Probability
0.91%

55.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TroposMesh Os<= 7.9.1
Tropos1310 Distrubution Automation Mesh RouterAll versions
Tropos1410 Mesh RouterAll versions
Tropos1410 Wireless Mesh RouterAll versions
Tropos3310 Indoor Mesh RouterAll versions
Tropos3320 Indoor Mesh RouterAll versions
Tropos4310 Mobile Mesh RouterAll versions
Tropos6310 Mesh RouterAll versions
Tropos6320 Mesh RouterAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-4898?
Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
How severe is CVE-2012-4898?
Severity scoring for CVE-2012-4898 is pending analysis. The EPSS model estimates a 0.91% probability of exploitation in the next 30 days.
How do I fix CVE-2012-4898?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-4898?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST