VulnerabilityModified
CVE-2005-4002
WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.
MEDIUM 4.0EPSS 0.98%
Does this matter?
Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.
Description
WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Affected
- esi products/webeoc
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/388282Patch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/388282Patch, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.