{"api_version":"1","generated_at":"2026-07-23T08:15:36+00:00","cve":"CVE-2014-2361","urls":{"html":"https://cve.report/CVE-2014-2361","api":"https://cve.report/api/cve/CVE-2014-2361.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2361","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2361"},"summary":{"title":"OleumTech WIO Family Key Management Errors","description":"OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.","state":"PUBLISHED","assigner":"icscert","published_at":"2014-07-24 14:55:07","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-320","NVD-CWE-Other","CWE-320 CWE-320"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}},{"version":"2.0","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}},{"version":"2.0","source":"CNA","type":"CVSS","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"accessComplexity":"LOW","accessVector":"LOCAL","authentication":"NONE","availabilityImpact":"COMPLETE","baseScore":7.2,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","version":"2.0"}}],"references":[{"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01","name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"OleumTech WIO Family Vulnerabilities | ICS-CERT","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/68797","name":"http://www.securityfocus.com/bid/68797","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/68795","name":"http://www.securityfocus.com/bid/68795","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple OleumTech Products CVE-2014-2361 Local Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://support.oleumtech.com/","name":"http://support.oleumtech.com/","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2361","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2361","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"OleumTech","product":"WIO DH2 Wireless Gateway","version":"affected All versions","platforms":[]},{"source":"CNA","vendor":"OleumTech","product":"Sensor Wireless I/O Modules","version":"affected All versions","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"OleumTech has created updates for both BreeZ and the gateway to mitigate\n all these vulnerabilities. These updates allow users to encrypt their \nwireless traffic with AES256. To obtain these updates, please log in to \nthe OleumTech download center ( http://support.oleumtech.com/  ) or contact OleumTech tech support:Phone: 866-508-8586\n\n\nEmail: TechSupport@OleumTech.com","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Lucas Apa and Carlos Mario Penagos Hollman of IOActive","lang":"en"}],"nvd_cpes":[{"cve_year":"2014","cve_id":"2361","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"oleumtech","cpe5":"sensor_wireless_i\\/o_module","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2361","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"oleumtech","cpe5":"wio_dh2_wireless_gateway","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:14:25.421Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01"},{"name":"68795","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/68795"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"WIO DH2 Wireless Gateway","vendor":"OleumTech","versions":[{"status":"affected","version":"All versions"}]},{"defaultStatus":"unaffected","product":"Sensor Wireless I/O Modules","vendor":"OleumTech","versions":[{"status":"affected","version":"All versions"}]}],"credits":[{"lang":"en","type":"finder","value":"Lucas Apa and Carlos Mario Penagos Hollman of IOActive"}],"datePublic":"2014-07-21T06:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>\nOleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.\n\n</p>"}],"value":"OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode."}],"metrics":[{"cvssV2_0":{"accessComplexity":"LOW","accessVector":"LOCAL","authentication":"NONE","availabilityImpact":"COMPLETE","baseScore":7.2,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-320","description":"CWE-320","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-06T17:31:55.409Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"name":"68797","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/68797"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a"},{"url":"http://support.oleumtech.com/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"OleumTech has created updates for both BreeZ and the gateway to mitigate\n all these vulnerabilities. These updates allow users to encrypt their \nwireless traffic with AES256. To obtain these updates, please log in to \nthe OleumTech download center (<a target=\"_blank\" rel=\"nofollow\" href=\"http://support.oleumtech.com/\">http://support.oleumtech.com/</a>&nbsp;) or contact OleumTech tech support:<p>Phone: 866-508-8586</p>\n<p>Email: <a target=\"_blank\" rel=\"nofollow\">TechSupport@OleumTech.com</a></p>"}],"value":"OleumTech has created updates for both BreeZ and the gateway to mitigate\n all these vulnerabilities. These updates allow users to encrypt their \nwireless traffic with AES256. To obtain these updates, please log in to \nthe OleumTech download center ( http://support.oleumtech.com/  ) or contact OleumTech tech support:Phone: 866-508-8586\n\n\nEmail: TechSupport@OleumTech.com"}],"source":{"advisory":"ICSA-14-202-01","discovery":"EXTERNAL"},"title":"OleumTech WIO Family Key Management Errors","x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-2360","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via packets that report a high battery voltage."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"68797","refsource":"BID","url":"http://www.securityfocus.com/bid/68797"},{"name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01","refsource":"MISC","url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-2361","datePublished":"2014-07-24T14:00:00.000Z","dateReserved":"2014-03-13T00:00:00.000Z","dateUpdated":"2025-10-06T17:31:55.409Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-07-24 14:55:07","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-320","NVD-CWE-Other","CWE-320 CWE-320"],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:oleumtech:sensor_wireless_i\\/o_module:-:*:*:*:*:*:*:*","matchCriteriaId":"82FA879C-B098-4A44-9036-43854ACBFD50"},{"vulnerable":true,"criteria":"cpe:2.3:h:oleumtech:wio_dh2_wireless_gateway:-:*:*:*:*:*:*:*","matchCriteriaId":"4055E1A3-F159-4B24-926C-578CE8632331"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2361","Ordinal":"1","Title":"OleumTech WIO Family Key Management Errors","CVE":"CVE-2014-2361","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2361","Ordinal":"1","NoteData":"OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.","Type":"Description","Title":"OleumTech WIO Family Key Management Errors"},{"CveYear":"2014","CveId":"2361","Ordinal":"2","NoteData":"2014-07-24","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2361","Ordinal":"3","NoteData":"2016-11-25","Type":"Other","Title":"Modified"}]}}}