SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-5461

An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.

MEDIUM 6.5EPSS 0.44%

Does this matter?

Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.

Description

An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS
0.44% probability · 37th percentile
CISA KEV
Not listed
Weakness
CWE-326
Affected
belden/hirschmann rs20-0900mmm2tdau · belden/hirschmann rs20-0900nnm4tdau · belden/hirschmann rs20-0900vvm2tdau · belden/hirschmann rs20-1600l2l2sdau · belden/hirschmann rs20-1600l2m2sdau · belden/hirschmann rs20-1600l2s2sdau · belden/hirschmann rs20-1600l2t1sdau · belden/hirschmann rs20-1600m2m2sdau · belden/hirschmann rs20-1600m2t1sdau · belden/hirschmann rs20-1600s2m2sdau · belden/hirschmann rs20-1600s2s2sdau · belden/hirschmann rs20-1600s2t1sdau · belden/hirschmann rsr20 · belden/hirschmann rsr30 · belden/hirschmann rsb20-0800m2m2saab · belden/hirschmann rsb20-0800m2m2saabe · belden/hirschmann rsb20-0800m2m2taab · belden/hirschmann rsb20-0800m2m2taabe · belden/hirschmann rsb20-0800s2s2saab · belden/hirschmann rsb20-0800s2s2saabe · +40 more
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.