CVE-2018-5461
Last modified
CVE-2018-5461 is a vulnerability of currently unknown severity. An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Belden | Hirschmann Rs20-0900mmm2tdau | All versions |
| Belden | Hirschmann Rs20-0900nnm4tdau | All versions |
| Belden | Hirschmann Rs20-0900vvm2tdau | All versions |
| Belden | Hirschmann Rs20-1600l2l2sdau | All versions |
| Belden | Hirschmann Rs20-1600l2m2sdau | All versions |
| Belden | Hirschmann Rs20-1600l2s2sdau | All versions |
| Belden | Hirschmann Rs20-1600l2t1sdau | All versions |
| Belden | Hirschmann Rs20-1600m2m2sdau | All versions |
| Belden | Hirschmann Rs20-1600m2t1sdau | All versions |
| Belden | Hirschmann Rs20-1600s2m2sdau | All versions |
| Belden | Hirschmann Rs20-1600s2s2sdau | All versions |
| Belden | Hirschmann Rs20-1600s2t1sdau | All versions |
| Belden | Hirschmann Rsr20 | All versions |
| Belden | Hirschmann Rsr30 | All versions |
| Belden | Hirschmann Rsb20-0800m2m2saab | All versions |
| Belden | Hirschmann Rsb20-0800m2m2saabe | All versions |
| Belden | Hirschmann Rsb20-0800m2m2taab | All versions |
| Belden | Hirschmann Rsb20-0800m2m2taabe | All versions |
| Belden | Hirschmann Rsb20-0800s2s2saab | All versions |
| Belden | Hirschmann Rsb20-0800s2s2saabe | All versions |
| Belden | Hirschmann Rsb20-0800s2s2taab | All versions |
| Belden | Hirschmann Rsb20-0800s2s2taabe | All versions |
| Belden | Hirschmann Rsb20-0800t1t1saab | All versions |
| Belden | Hirschmann Rsb20-0800t1t1saabe | All versions |
| Belden | Hirschmann Rsb20-0800t1t1taab | All versions |
| Belden | Hirschmann Rsb20-0800t1t1taabe | All versions |
| Belden | Hirschmann Rsb20-0900m2ttsaab | All versions |
| Belden | Hirschmann Rsb20-0900m2ttsaabe | All versions |
| Belden | Hirschmann Rsb20-0900m2tttaab | All versions |
| Belden | Hirschmann Rsb20-0900m2tttaabe | All versions |
| Belden | Hirschmann Rsb20-0900mmm2saab | All versions |
| Belden | Hirschmann Rsb20-0900mmm2saabe | All versions |
| Belden | Hirschmann Rsb20-0900mmm2taab | All versions |
| Belden | Hirschmann Rsb20-0900mmm2taabe | All versions |
| Belden | Hirschmann Rsb20-0900s2ttsaab | All versions |
| Belden | Hirschmann Rsb20-0900s2ttsaabe | All versions |
| Belden | Hirschmann Rsb20-0900s2tttaab | All versions |
| Belden | Hirschmann Rsb20-0900s2tttaabe | All versions |
| Belden | Hirschmann Rsb20-0900vvm2saab | All versions |
| Belden | Hirschmann Rsb20-0900vvm2saabe | All versions |
| Belden | Hirschmann Rsb20-0900vvm2taab | All versions |
| Belden | Hirschmann Rsb20-0900vvm2taabe | All versions |
| Belden | Hirschmann Rsb20-0900zzz6saab | All versions |
| Belden | Hirschmann Rsb20-0900zzz6saabe | All versions |
| Belden | Hirschmann Rsb20-0900zzz6taab | All versions |
| Belden | Hirschmann Rsb20-0900zzz6taabe | All versions |
| Belden | Hirschmann M1-8mm-Sc | All versions |
| Belden | Hirschmann M1-8sfp | All versions |
| Belden | Hirschmann M1-8sm-Sc | All versions |
| Belden | Hirschmann M1-8tp-Rj45 | All versions |
Showing 50 of 134 affected configurations. See NVD for the full list.
References
- http://www.securityfocus.com/bid/103340Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-065-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/103340Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-065-01Mitigation, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5461?
How severe is CVE-2018-5461?
How do I fix CVE-2018-5461?
Are you affected by CVE-2018-5461?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
