CVE-2010-2306

Severity CVSS v4.0:
Pending analysis
Type:
CWE-16 Configuration Errors
Publication date:
16/06/2010
Last modified:
11/04/2025

Description

The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for multiple devices and installations, which allows remote attackers to decrypt SSL traffic via a man-in-the-middle (MITM) attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:sourcefire:3d1000:*:*:*:*:*:*:*:*
cpe:2.3:h:sourcefire:3d2000:*:*:*:*:*:*:*:*
cpe:2.3:h:sourcefire:3d9900:*:*:*:*:*:*:*:*
cpe:2.3:h:sourcefire:dc1000:*:*:*:*:*:*:*:*