CVE-2015-6476

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/11/2015
Last modified:
12/04/2025

Description

Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:advantech:eki-1321_series_firmware:*:*:*:*:*:*:*:* 1.96 (including)
cpe:2.3:o:advantech:eki-1322_series_firmware:*:*:*:*:*:*:*:* 1.96 (including)
cpe:2.3:h:advantech:eki-1321:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1322:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-1361_series_firmware:*:*:*:*:*:*:*:* 1.17 (including)
cpe:2.3:o:advantech:eki-1362_series_firmware:*:*:*:*:*:*:*:* 1.17 (including)
cpe:2.3:h:advantech:eki-1361:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1362:*:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-122x_series_firmware:*:*:*:*:*:*:*:* 1.49 (including)
cpe:2.3:h:advantech:eki-1221:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1221d:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1222:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1222d:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1224:-:*:*:*:*:*:*:*