CVE-2015-6476

Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-15-309-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:advantech:eki-1321_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-1322_series_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:advantech:eki-1321:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1322:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:advantech:eki-1361_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:advantech:eki-1362_series_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:advantech:eki-1361:*:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1362:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:advantech:eki-122x_series_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:advantech:eki-1221:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1221d:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1222:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1222d:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:eki-1224:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-11-07 03:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-6476

Mitre link : CVE-2015-6476

CVE.ORG link : CVE-2015-6476


JSON object : View

Products Affected

advantech

  • eki-1361
  • eki-1321_series_firmware
  • eki-1321
  • eki-1322_series_firmware
  • eki-1221d
  • eki-1224
  • eki-1221
  • eki-1362_series_firmware
  • eki-122x_series_firmware
  • eki-1222
  • eki-1361_series_firmware
  • eki-1362
  • eki-1322
  • eki-1222d