CVE-2016-5816: High severity westermo mrd-305-din firmware vulnerability
A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys that may allow an attacker to decrypt traffic from any other source.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5816?
CVE-2016-5816 is considered a critical vulnerability due to the use of hard-coded cryptographic keys.
How do I fix CVE-2016-5816?
To fix CVE-2016-5816, upgrade the vulnerable device firmware to version 1.7.5.0 or later.
What devices are affected by CVE-2016-5816?
CVE-2016-5816 affects MRD-305-DIN versions older than 1.7.5.0 and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0.
What risks are associated with CVE-2016-5816?
The risks of CVE-2016-5816 include potential decryption of traffic, leading to unauthorized access to sensitive data.
Is there a workaround for CVE-2016-5816?
There is no effective workaround for CVE-2016-5816 other than updating the device firmware to a secure version.