CVE Feed

    Dashboard / CVE / CVE-2012-3006

    CVE-2012-3006

    The Innominate mGuard Smart HW before HW-101130 and BD before BD-101030, mGuard industrial RS, mGuard delta HW before HW-103060 and BD before BD-211010, mGuard PCI, mGuard blade, and EAGLE mGuard appliances with software before 7.5.0 do not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof (1) HTTPS or (2) SSH servers by predicting a key value.

    Published:Jun 19, 2012
    Last Modified:Apr 11, 2025
    EPS:Jun 19, 2012
    EPSS Score:0.0054
    CVSS Score:7.1

    Affected Products

    Vendor
    Innominate
    Product
    Eagle Mguard Bd-301010
    Vendor
    Innominate
    Product
    Eagle Mguard Hw-201000
    Vendor
    Innominate
    Product
    Mguard Blade Hw-104020
    Vendor
    Innominate
    Product
    Mguard Blade Hw-104050
    Vendor
    Innominate
    Product
    Mguard Delta Bd-201000
    Vendor
    Innominate
    Product
    Mguard Delta Hw-103050
    Vendor
    Innominate
    Product
    Mguard Firmware
    Vendor
    Innominate
    Product
    Mguard Industrial Rs Bd-501000
    Vendor
    Innominate
    Product
    Mguard Industrial Rs Bd-501010
    Vendor
    Innominate
    Product
    Mguard Industrial Rs Bd-501020
    Vendor
    Innominate
    Product
    Mguard Industrial Rs Hw-105000
    Vendor
    Innominate
    Product
    Mguard Pci Bd-111010
    Vendor
    Innominate
    Product
    Mguard Pci Bd-111020
    Vendor
    Innominate
    Product
    Mguard Pci Hw-102020
    Vendor
    Innominate
    Product
    Mguard Pci Hw-102050
    Vendor
    Innominate
    Product
    Mguard Smart Bd-101010
    Vendor
    Innominate
    Product
    Mguard Smart Bd-101020
    Vendor
    Innominate
    Product
    Mguard Smart Hw-101020
    Vendor
    Innominate
    Product
    Mguard Smart Hw-101050

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High