CVE-2013-2782
Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- schneider-electric/tburjr900 · schneider-electric/tburjr900 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-234-01US Government Resource
- http://www.schneider-electric.com/download/ww/en/file/141141292-SEVD-2013-143-01.pdfVendor Advisory
- http://ics-cert.us-cert.gov/advisories/ICSA-13-234-01US Government Resource
- http://www.schneider-electric.com/download/ww/en/file/141141292-SEVD-2013-143-01.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.