CVE-2015-3960
Last modified
CVE-2015-3960 is a vulnerability of currently unknown severity. The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches uses hardcoded RSA private keys and certificates across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms for HTTPS sessions by leveraging knowledge of a private key from another installation.. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches uses hardcoded RSA private keys and certificates across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms for HTTPS sessions by leveraging knowledge of a private key from another installation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Garrettcom | Magnum 10k Firmware | <= 4.5.5 |
| Garrettcom | Magnum 6k Firmware | <= 4.5.5 |
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-167-01Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-167-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-3960?
How severe is CVE-2015-3960?
How do I fix CVE-2015-3960?
Are you affected by CVE-2015-3960?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
