Hard-coded Cryptographic Key Vulnerability in Red Lion Controls Industrial Switches
CVE-2016-9335

10CRITICAL

What is CVE-2016-9335?

A hard-coded cryptographic key vulnerability exists in Red Lion Controls' Sixnet-Managed Industrial Switches and Stride-Managed Ethernet Switches. The affected products, running specific firmware versions, utilize the same non-regenerable HTTP SSL/SSH keys for secure communication, increasing the risk of unauthorized access and potential system compromise. To mitigate this risk, users are urged to upgrade to the recommended SLX firmware Version 5.3.174, as this will enhance the security of network communications.

Affected Version(s)

Sixnet-Managed Industrial Switches firmware Version 5.0.196 and prior

STRIDE-Managed Ethernet Switch models firmware Version 5.0.190 and prior.

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.