Tropos Wireless Mesh Routers Insufficient Entropy
Summary
| CVE | CVE-2012-4898 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-12-18 12:30:05 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere. |
Risk And Classification
Primary CVSS: v2.0 6.1 from [email protected]
AV:N/AC:H/Au:N/C:C/I:P/A:N
Problem Types: CWE-310 | CWE 331
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 6.1 | AV:N/AC:H/Au:N/C:C/I:P/A:N | |
| 2.0 | [email protected] | Secondary | 6.1 | AV:N/AC:H/Au:N/C:C/I:P/A:N | |
| 2.0 | CNA | CVSS | 6.1 | AV:N/AC:H/Au:N/C:C/I:P/A:N |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:C/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Tropos | 1310 Distrubution Automation Mesh Router | - | All | All | All |
| Hardware | Tropos | 1410 Mesh Router | - | All | All | All |
| Hardware | Tropos | 1410 Wireless Mesh Router | - | All | All | All |
| Hardware | Tropos | 3310 Indoor Mesh Router | - | All | All | All |
| Hardware | Tropos | 3320 Indoor Mesh Router | - | All | All | All |
| Hardware | Tropos | 4310 Mobile Mesh Router | - | All | All | All |
| Hardware | Tropos | 6310 Mesh Router | - | All | All | All |
| Hardware | Tropos | 6320 Mesh Router | - | All | All | All |
| Operating System | Tropos | Mesh Os | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/news-events/ics-advisories/icsa-12-297-01 | [email protected] | www.cisa.gov | |
| Tropos Wireless Mesh Routers | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: research group composed of Nadia Heninger (University of California at San Diego), Zakir Durumeric (University of Michigan), Eric Wustrow (University of Michigan), and J. Alex Halderman (University of Michigan) (en)
Additional Advisory Data
Solutions
CNA: Tropos Networks has released customer notification and an update (Tropos Mesh OS 7.9.1.1) for its network device embedded software. This update can be downloaded from the Tropos software download page. Download of the update requires a valid user name and password. The updated firmware fixes the vulnerability by using sufficient entropy to generate unique SSH host keys.
There are currently no legacy QID mappings associated with this CVE.