Post Oak Bluetooth Traffic Systems Insufficient Entropy
Summary
| CVE | CVE-2012-4687 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-12-08 15:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof a device by predicting a key value. |
Risk And Classification
Primary CVSS: v2.0 7.6 from [email protected]
AV:N/AC:H/Au:N/C:C/I:C/A:C
Problem Types: CWE-331 | CWE-310 | CWE-331 CWE-331
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.6 | AV:N/AC:H/Au:N/C:C/I:C/A:C | |
| 2.0 | [email protected] | Secondary | 7.6 | AV:N/AC:H/Au:N/C:C/I:C/A:C | |
| 2.0 | CNA | CVSS | 7.6 | AV:N/AC:H/Au:N/C:C/I:C/A:C |
CVSS v2.0 Breakdown
AV:N/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Postoaktraffic | Awam Bluetooth Reader | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Post Oak Traffic Systems | AWAM Bluetooth Reader Traffic System | affected All versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.postoaktraffic.com/contact.aspx | [email protected] | www.postoaktraffic.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-12-335-01 | [email protected] | www.cisa.gov | |
| 404 - File Not Found | CISA | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: research group composed of Nadia Heninger (University of California at San Diego), J. Alex Halderman, Zakir Durumeric, and Eric Wustrow (all from the University of Michigan) (en)
Additional Advisory Data
Solutions
CNA: Post Oak has developed a patch for the AWAM Bluetooth Reader Traffic System that mitigates the vulnerability. The patch allows the Bluetooth reader to ensure sufficient entropy exists before generating host and authentication keys. The patch will be installed on all new devices when initially configured. Existing equipment will be patched by remote access and upgraded to the latest firmware. System owners are encouraged to contact Post Oak Traffic Systems, [email protected], (281) 381-2887. with questions patching their systems.