CVE-2015-7923: Critical severity westermo weos vulnerability
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7923?
CVE-2015-7923 is identified as a critical vulnerability due to its potential to enable man-in-the-middle attacks.
How do I fix CVE-2015-7923?
To mitigate CVE-2015-7923, upgrade to Westermo WeOS version 4.19.0 or later where the private key issue is resolved.
Who is affected by CVE-2015-7923?
CVE-2015-7923 affects any installations of Westermo WeOS versions prior to 4.19.0.
What kind of attacks can CVE-2015-7923 facilitate?
CVE-2015-7923 can facilitate man-in-the-middle attacks by exploiting the use of a shared SSL private key among different customers.
What is the impact of CVE-2015-7923 on data confidentiality?
CVE-2015-7923 can compromise data confidentiality by allowing attackers to decrypt sensitive communication without detection.