Reset mguard smart7/19/2023 This vulnerability could be exploited remotely by a MitM type attack. Vulnerability Details ExploitabilityĪn attacker can predict the user’s session ID and potentially hijack the session. Keys that are loaded as part of the mGuard configuration (i.e., VPN) are not affected. This could allow the attacker to execute arbitrary code or gain unauthorized access to the system. By calculating private keys, an attacker could perform a MitM attack on the system. The mGuard products do not use sufficient entropy when generating keys for HTTPS and SSH, therefore making them too weak. Vulnerability Characterization Vulnerability Overview Innominate reports that the mGuard products are used many countries worldwide. Innominate’s products are deployed in many sectors including manufacturing, electric power generation, water, transportation, healthcare, communications, and satellite operations. Innominate’s mGuard product line includes firewall and VPN network security appliances. Innominate is a company based in Berlin, Germany, founded in 2001. ICS-CERT recommends that organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation. This vulnerability can weaken the security posture of any industrial network in which these products are deployed.Impact to individual organizations depends on many factors that are unique to each organization. All products manufactured prior to 2006.Affected ProductsĪll versions of the following Innominate products are affected: This vulnerability can be remotely exploited.ICS-CERT has coordinated this vulnerability with Innominate, which has produced an update that resolves this vulnerability. Innominate has validated the vulnerability and produced an update that resolves the reported vulnerability. By impersonating the device, an attacker can obtain the credentials of administrative users and potentially perform a Man-in-the-Middle (MitM) attack. Alex Halderman identified an insufficient entropy vulnerability in Innominate’s mGuard network appliance product line. An independent research group comprised of Nadia Heninger, Zakir Durumeric, Eric Wustrow, and J.
0 Comments
Leave a Reply. |