漏洞标题
山脊 ComNav 加密强度不足
漏洞描述信息
Hills ComNav加密强度不足
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
N/A
漏洞标题
Hills ComNav Inadequate Encryption Strength
漏洞描述信息
Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are predictable. This would allow an attacker to learn the state of the system if they can observe the traffic. This would be possible even if the traffic were encrypted, e.g., using WPA2, as the packet sizes would remain observable. The communication encryption scheme is theoretically sound, but is not strong enough for the level of protection required.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
不充分的加密强度
漏洞标题
Interlogix Hills ComNav 加密问题漏洞
漏洞描述信息
Interlogix Hills ComNav是澳大利亚Interlogix公司的一个 Hills Reliance 安全警报系统的远程访问集成模块。 Interlogix Hills ComNav存在加密问题漏洞,攻击者可以查看跨本地网络的配置页面流量。
CVSS信息
N/A
漏洞类别
加密问题