CVE-2009-4295
Summary
| CVE | CVE-2009-4295 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-11 16:30:00 UTC |
| Updated | 2009-12-14 05:00:00 UTC |
| Description | Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which makes it easier for remote attackers to obtain sensitive information by predicting a key and then using it to decrypt sniffed network traffic. |
Risk And Classification
Problem Types: CWE-310
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Ray Server Software | 4.0 | All | linux | All |
| Application | Sun | Ray Server Software | 4.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 4.0 | All | x86 | All |
| Application | Sun | Ray Server Software | 4.1 | All | linux | All |
| Application | Sun | Ray Server Software | 4.1 | All | sparc | All |
| Application | Sun | Ray Server Software | 4.1 | All | x86 | All |
| Application | Sun | Ray Server Software | 4.0 | All | linux | All |
| Application | Sun | Ray Server Software | 4.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 4.0 | All | x86 | All |
| Application | Sun | Ray Server Software | 4.1 | All | linux | All |
| Application | Sun | Ray Server Software | 4.1 | All | sparc | All |
| Application | Sun | Ray Server Software | 4.1 | All | x86 | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| sunsolve.sun.com/search/document.do | CONFIRM | sunsolve.sun.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| 270549 | SUNALERT | sunsolve.sun.com | Vendor Advisory |
| Sun Ray Server Firmware Insecure Key Generation Vulnerability | BID | www.securityfocus.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.