← All CVEs

CVE-2013-0137

high · 10

The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 contains a known SSH private key, which makes it easier for remote attackers to obtain root access, and spoof alerts, via an SSH session.

10
CVSS
13.4%
EPSS (exploit prob.)
96th
EPSS percentile
2013-06-30
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-310

Affected products

VendorProductAffected versions
digital_alert_systemsdasdec_eas<= 2.0-1
digital_alert_systemsdasdec_eas2.0-0
monroe_electronicsr189_one-net_eas<= 2.0-1
monroe_electronicsr189_one-net_eas2.0-0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-0137