CVE-2014-10069

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
07/01/2018
Last modified:
02/02/2018

Description

Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers to obtain sensitive information by decrypting a backup configuration file, as demonstrated by a password hash in the um_auth_account_password field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hitrontech:cve-30360_firmware:3.1.1.21:*:*:*:*:*:*:*
cpe:2.3:h:hitrontech:cve-30360:-:*:*:*:*:*:*:*