[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-2306Date: (C)2010-06-16   (M)2023-12-22


The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for multiple devices and installations, which allows remote attackers to decrypt SSL traffic via a man-in-the-middle (MITM) attack.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 5.5
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: ADJACENT_NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1024092
http://www.securityfocus.com/archive/1/511792/100/0/threaded
SECUNIA-40143
OSVDB-65470
ADV-2010-1438
http://www.zerodayinitiative.com/advisories/ZDI-10-107/
https://support.sourcefire.com/notices/notice/1437
sourcefire3d-ssl-mitm(59380)

CWE    1
CWE-16

© SecPod Technologies