Back to overview

CVE-2014-5419

10.0
CVSS 2.0
Description
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different customers' installations, which makes it easier for remote attackers to obtain the cleartext content of network traffic by reading this key from a firmware image and then sniffing the network.

Metadata

CVE ID
CVE-2014-5419
State
PUBLISHED
Assigner
icscert
Reserved
2014-08-22 00:00 UTC
Published
2015-01-17 02:00 UTC
Last updated
2025-11-04 23:32 UTC
Primary CWE
CWE-321
CWE-321
Vendor / Product
GE / Multilink ML800/1200/1600/2400
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 N/D CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products (2)
VendorProductPlatformVersions
GE ML810/3000/3100 series switch 0 ≤ 5.2.0
GE Multilink ML800/1200/1600/2400 0 ≤ 4.2.1
Weakness (CWE)
CWESourceDescription
CWE-321 cna CWE-321
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 N/D 2.0 cna AV:N/AC:L/Au:N/C:C/I:C/A:C
Back to overview