CVE-2020-25193

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
18/03/2022
Last modified:
21/10/2022

Description

By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encrypted traffic through an HTTPS connection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ge:rt430_firmware:*:*:*:*:*:*:*:* 08a06 (excluding)
cpe:2.3:h:ge:rt430:-:*:*:*:*:*:*:*
cpe:2.3:o:ge:rt431_firmware:*:*:*:*:*:*:*:* 08a06 (excluding)
cpe:2.3:h:ge:rt431:-:*:*:*:*:*:*:*
cpe:2.3:o:ge:rt434_firmware:*:*:*:*:*:*:*:* 08a06 (excluding)
cpe:2.3:h:ge:rt434:-:*:*:*:*:*:*:*