SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-2361

OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use…

HIGH 7.2EPSS 0.40%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.

CVSS 2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.40% probability · 34th percentile
CISA KEV
Not listed
Weakness
CWE-320
Affected
oleumtech/sensor wireless i\/o module · oleumtech/wio dh2 wireless gateway
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.