CVE-2013-4218: Low severity intel wimax network service vulnerability
The InitMethodAndPassword function in InfraStack/OSAgnostic/WiMax/Agents/Supplicant/Source/SupplicantAgent.c in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses the same RSA private key in supplicantkey.pem on all systems, which allows local users to obtain sensitive information via unspecified decryption operations.
Other sources
The wimax package installs a RSA private key in /usr/share/wimax/supplicantkey.pem. We should never ship hard-coded private keys. The embedded CA certificate in /usr/share/wimax/cacert.pem is suspicious as well. It is unclear how device key management is supposed to work.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4218?
CVE-2013-4218 is classified as a medium severity vulnerability.
How do I fix CVE-2013-4218?
To address CVE-2013-4218, update the Intel WiMAX Network Service to version 1.5.2 or later.
What are the impacts of CVE-2013-4218?
CVE-2013-4218 allows local users to exploit the use of the same RSA private key across systems, potentially compromising security.
Which versions of software are affected by CVE-2013-4218?
CVE-2013-4218 affects Intel WiMAX Network Service versions up to and including 1.5.2.
Who should be concerned about CVE-2013-4218?
Local users and administrators of devices running affected versions of the Intel WiMAX Network Service should be concerned about CVE-2013-4218.