OleumTech WIO Use of Cryptographically Weak Pseudo-Random Number Generator
Summary
| CVE | CVE-2014-2362 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-24 14:55:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation. |
Risk And Classification
Primary CVSS: v2.0 7.8 from [email protected]
AV:N/AC:M/Au:N/C:C/I:P/A:N
Problem Types: CWE-338 | NVD-CWE-Other | CWE-338 CWE-338
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.8 | AV:N/AC:M/Au:N/C:C/I:P/A:N | |
| 2.0 | [email protected] | Secondary | 7.8 | AV:N/AC:M/Au:N/C:C/I:P/A:N | |
| 2.0 | CNA | CVSS | 7.8 | AV:N/AC:M/Au:N/C:C/I:P/A:N |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:C/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Oleumtech | Sensor Wireless I/o Module | - | All | All | All |
| Hardware | Oleumtech | Wio Dh2 Wireless Gateway | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | OleumTech | WIO DH2 Wireless Gateway | affected All versions | Not specified |
| CNA | OleumTech | Sensor Wireless I/O Modules | affected All versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple OleumTech Products CVE-2014-2362 Predictable Random Number Generator Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| OleumTech WIO Family Vulnerabilities | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| www.securityfocus.com/bid/68797 | [email protected] | www.securityfocus.com | |
| support.oleumtech.com | [email protected] | support.oleumtech.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Lucas Apa and Carlos Mario Penagos Hollman of IOActive (en)
Additional Advisory Data
Solutions
CNA: OleumTech has created updates for both BreeZ and the gateway to mitigate all these vulnerabilities. These updates allow users to encrypt their wireless traffic with AES256. To obtain these updates, please log in to the OleumTech download center ( http://support.oleumtech.com/ ) or contact OleumTech tech support:Phone: 866-508-8586 Email: [email protected]
There are currently no legacy QID mappings associated with this CVE.