OleumTech WIO Family Key Management Errors
Summary
| CVE | CVE-2014-2361 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-24 14:55:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: CWE-320 | NVD-CWE-Other | CWE-320 CWE-320
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C | |
| 2.0 | [email protected] | Secondary | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C | |
| 2.0 | CNA | CVSS | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C |
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Oleumtech | Sensor Wireless I/o Module | - | All | All | All |
| Hardware | Oleumtech | Wio Dh2 Wireless Gateway | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | OleumTech | WIO DH2 Wireless Gateway | affected All versions | Not specified |
| CNA | OleumTech | Sensor Wireless I/O Modules | affected All versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OleumTech WIO Family Vulnerabilities | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| www.securityfocus.com/bid/68797 | [email protected] | www.securityfocus.com | |
| Multiple OleumTech Products CVE-2014-2361 Local Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| support.oleumtech.com | [email protected] | support.oleumtech.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Lucas Apa and Carlos Mario Penagos Hollman of IOActive (en)
Additional Advisory Data
Solutions
CNA: OleumTech has created updates for both BreeZ and the gateway to mitigate all these vulnerabilities. These updates allow users to encrypt their wireless traffic with AES256. To obtain these updates, please log in to the OleumTech download center ( http://support.oleumtech.com/ ) or contact OleumTech tech support:Phone: 866-508-8586 Email: [email protected]
There are currently no legacy QID mappings associated with this CVE.