CVE Database
/

CVE-2016-9335

Back to search

CVE-2016-9335

Published: May 9, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190. Vulnerable versions of Stride-Managed Ethernet switches and Sixnet-Managed Industrial switches use hard-coded HTTP SSL/SSH keys for secure communication. Because these keys cannot be regenerated by users, all products use the same key. The attacker could disrupt communication or compromise the system. CVSS v3 base score: 10, CVSS vector string: (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Red Lion Controls recommends updating to SLX firmware Version 5.3.174.

VendorProductVersions

Red Lion Controls

Sixnet-Managed Industrial Switches

affected
firmware Version 5.0.196 and prior

AutomationDirect

STRIDE-Managed Ethernet Switch models

affected
firmware Version 5.0.190 and prior.

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now