Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-30271


The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.


Published

2022-07-26T23:15:08.177

Last Modified

2024-11-21T07:02:28.210

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-798
  • Type: Secondary
    CWE-259

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System motorola ace1000_firmware - Yes
Hardware motorola ace1000 - No

References