PT-2009-3975 · Aten · Aten Kh1516I Ip Kvm Switch+2
Published
2009-05-27
·
Updated
2018-10-10
·
CVE-2009-1477
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
ATEN KH1516i IP KVM switch version 1.0.063
ATEN KN9116 IP KVM switch version 1.1.104
ATEN PN9108 power-control unit (affected versions not specified)
Description:
The issue concerns a hardcoded SSL private key in the https web interfaces of certain ATEN products. This hardcoded key allows remote attackers to more easily decrypt https sessions. Attackers can extract the key from their own device and then use it to sniff network traffic to a device owned by a different customer, potentially accessing sensitive information.
Recommendations:
For ATEN KH1516i IP KVM switch version 1.0.063, consider disabling the https web interface until a patch is available.
For ATEN KN9116 IP KVM switch version 1.1.104, restrict access to the https web interface to minimize the risk of exploitation.
For ATEN PN9108 power-control unit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aten Kh1516I Ip Kvm Switch
Aten Kn9116 Ip Kvm Switch
Aten Pn9108 Power-Control Unit