CVE-2015-6476

A

dvantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.

References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-15-309-01 Third Party Advisory US Government Resource
https://ics-cert.us-cert.gov/advisories/ICSA-15-309-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:advantech:eki-1321_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-1322_series_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:advantech:eki-1321:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1322:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:advantech:eki-1361_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-1362_series_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:advantech:eki-1361:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1362:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:advantech:eki-122x_series_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:advantech:eki-1221:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1221d:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1222:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1222d:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1224:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:35

Type Values Removed Values Added
References () https://ics-cert.us-cert.gov/advisories/ICSA-15-309-01 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSA-15-309-01 - Third Party Advisory, US Government Resource