4.3
CVSSv2

CVE-2014-2716

Published: 19/12/2014 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote malicious users to obtain plaintext messages via an XOR operation on two ciphertexts.

Vulnerable Product Search on Vulmon Subscribe to Product

ekahau real-time location system controller 6.0.5-final

ekahau activator 3

ekahau b4_staff_badge_tag_firmware 1.4.52

Exploits

Ekahau Real-Time Location System suffers from RC4 cipher stream reuse and weak key derivation flaws The message payload of the affected solution is always encrypted using the same RC4 cipher stream When combining two encrypted messages with an XOR operation, the cipher stream will cancel out With this, an attacker is able to recover the bitwise ...