PT-2009-3975 · Aten · Aten Kh1516I Ip Kvm Switch+2
Publicado
2009-05-27
·
Atualizado
2018-10-10
·
CVE-2009-1477
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
ATEN KH1516i IP KVM switch version 1.0.063
ATEN KN9116 IP KVM switch version 1.1.104
ATEN PN9108 power-control unit (affected versions not specified)
Description:
The issue concerns a hardcoded SSL private key in the https web interfaces of certain ATEN products. This hardcoded key allows remote attackers to more easily decrypt https sessions. Attackers can extract the key from their own device and then use it to sniff network traffic to a device owned by a different customer, potentially accessing sensitive information.
Recommendations:
For ATEN KH1516i IP KVM switch version 1.0.063, consider disabling the https web interface until a patch is available.
For ATEN KN9116 IP KVM switch version 1.1.104, restrict access to the https web interface to minimize the risk of exploitation.
For ATEN PN9108 power-control unit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aten Kh1516I Ip Kvm Switch
Aten Kn9116 Ip Kvm Switch
Aten Pn9108 Power-Control Unit