First published: Sat Jan 30 2016(Updated: )
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Westermo WeOS | =4.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7923 is identified as a critical vulnerability due to its potential to enable man-in-the-middle attacks.
To mitigate CVE-2015-7923, upgrade to Westermo WeOS version 4.19.0 or later where the private key issue is resolved.
CVE-2015-7923 affects any installations of Westermo WeOS versions prior to 4.19.0.
CVE-2015-7923 can facilitate man-in-the-middle attacks by exploiting the use of a shared SSL private key among different customers.
CVE-2015-7923 can compromise data confidentiality by allowing attackers to decrypt sensitive communication without detection.