CVE-2015-8288
NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms…
Does this matter?
Lower severity and a low EPSS score (1.89%). Track it; it rarely justifies an emergency change on its own.
Description
NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.89% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- netgear/d3600 firmware · netgear/d6000 firmware
- Source
- cret@cert.org
References
- http://kb.netgear.com/app/answers/detail/a_id/30560Vendor Advisory
- http://www.kb.cert.org/vuls/id/778696Third Party Advisory, US Government Resource
- http://kb.netgear.com/app/answers/detail/a_id/30560Vendor Advisory
- http://www.kb.cert.org/vuls/id/778696Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.