CVE-2020-25193
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
18/03/2022
Last modified:
21/10/2022
Description
By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encrypted traffic through an HTTPS connection.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ge:rt430_firmware:*:*:*:*:*:*:*:* | 08a06 (excluding) | |
| cpe:2.3:h:ge:rt430:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ge:rt431_firmware:*:*:*:*:*:*:*:* | 08a06 (excluding) | |
| cpe:2.3:h:ge:rt431:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ge:rt434_firmware:*:*:*:*:*:*:*:* | 08a06 (excluding) | |
| cpe:2.3:h:ge:rt434:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



