CVE-2016-2333
Last modified
CVE-2016-2333 is a vulnerability of currently unknown severity. SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different customers' installations, which allows attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different customers' installations, which allows attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Systech | Syslink Sl-1000 Modular Gateway Firmware | All versions |
References
- http://www.kb.cert.org/vuls/id/822980Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/822980Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2333?
How severe is CVE-2016-2333?
How do I fix CVE-2016-2333?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-2327libavcodec/pngenc.c in FFmpeg before 2.8.5 uses incorrect li…
- CVE-2016-2328libswscale/swscale_unscaled.c in FFmpeg before 2.8.6 does no…
- CVE-2016-2329libavcodec/tiff.c in FFmpeg before 2.8.6 does not properly v…
- CVE-2016-2330libavcodec/gif.c in FFmpeg before 2.8.6 does not properly ca…
- CVE-2016-2331The web interface on SysLINK SL-1000 Machine-to-Machine (M2M…
- CVE-2016-2332flu.cgi in the web interface on SysLINK SL-1000 Machine-to-M…
- CVE-2016-2334Heap-based buffer overflow in the NArchive::NHfs::CHandler::…
- CVE-2016-2335The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp…
- CVE-2016-2336Type confusion exists in two methods of Ruby's WIN32OLE clas…
- CVE-2016-2337Type confusion exists in _cancel_eval Ruby's TclTkIp class m…
- CVE-2016-2338An exploitable heap overflow vulnerability exists in the Psy…9.8
- CVE-2016-2339An exploitable heap overflow vulnerability exists in the Fid…
Are you affected by CVE-2016-2333?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
