PT-2009-3975 · Aten · Aten Kh1516I Ip Kvm Switch+2

Publicado

2009-05-27

·

Atualizado

2018-10-10

·

CVE-2009-1477

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: ATEN KH1516i IP KVM switch version 1.0.063 ATEN KN9116 IP KVM switch version 1.1.104 ATEN PN9108 power-control unit (affected versions not specified)
Description: The issue concerns a hardcoded SSL private key in the https web interfaces of certain ATEN products. This hardcoded key allows remote attackers to more easily decrypt https sessions. Attackers can extract the key from their own device and then use it to sniff network traffic to a device owned by a different customer, potentially accessing sensitive information.
Recommendations: For ATEN KH1516i IP KVM switch version 1.0.063, consider disabling the https web interface until a patch is available. For ATEN KN9116 IP KVM switch version 1.1.104, restrict access to the https web interface to minimize the risk of exploitation. For ATEN PN9108 power-control unit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1477

Produtos afetados

Aten Kh1516I Ip Kvm Switch
Aten Kn9116 Ip Kvm Switch
Aten Pn9108 Power-Control Unit