{"api_version":"1","generated_at":"2026-07-23T09:40:11+00:00","cve":"CVE-2014-2362","urls":{"html":"https://cve.report/CVE-2014-2362","api":"https://cve.report/api/cve/CVE-2014-2362.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2362","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2362"},"summary":{"title":"OleumTech WIO Use of Cryptographically Weak Pseudo-Random Number Generator","description":"OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.","state":"PUBLISHED","assigner":"icscert","published_at":"2014-07-24 14:55:07","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-338","NVD-CWE-Other","CWE-338 CWE-338"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:P/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}},{"version":"2.0","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"7.8","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:P/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}},{"version":"2.0","source":"CNA","type":"CVSS","score":"7.8","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:P/A:N","data":{"accessComplexity":"MEDIUM","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"NONE","baseScore":7.8,"confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","vectorString":"AV:N/AC:M/Au:N/C:C/I:P/A:N","version":"2.0"}}],"references":[{"url":"http://www.securityfocus.com/bid/68800","name":"http://www.securityfocus.com/bid/68800","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple OleumTech Products CVE-2014-2362 Predictable Random Number Generator Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01","name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"OleumTech WIO Family Vulnerabilities | ICS-CERT","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/68797","name":"http://www.securityfocus.com/bid/68797","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://support.oleumtech.com/","name":"http://support.oleumtech.com/","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2362","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2362","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"OleumTech","product":"WIO DH2 Wireless Gateway","version":"affected All versions","platforms":[]},{"source":"CNA","vendor":"OleumTech","product":"Sensor Wireless I/O Modules","version":"affected All versions","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"OleumTech has created updates for both BreeZ and the gateway to mitigate\n all these vulnerabilities. These updates allow users to encrypt their \nwireless traffic with AES256. To obtain these updates, please log in to \nthe OleumTech download center ( http://support.oleumtech.com/  ) or contact OleumTech tech support:Phone: 866-508-8586\n\n\nEmail: TechSupport@OleumTech.com","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Lucas Apa and Carlos Mario Penagos Hollman of IOActive","lang":"en"}],"nvd_cpes":[{"cve_year":"2014","cve_id":"2362","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"oleumtech","cpe5":"sensor_wireless_i\\/o_module","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2362","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"oleumtech","cpe5":"wio_dh2_wireless_gateway","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:14:25.268Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"68800","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/68800"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"WIO DH2 Wireless Gateway","vendor":"OleumTech","versions":[{"status":"affected","version":"All versions"}]},{"defaultStatus":"unaffected","product":"Sensor Wireless I/O Modules","vendor":"OleumTech","versions":[{"status":"affected","version":"All versions"}]}],"credits":[{"lang":"en","type":"finder","value":"Lucas Apa and Carlos Mario Penagos Hollman of IOActive"}],"datePublic":"2014-07-21T06:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>\n\nOleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.\n\n</p>"}],"value":"OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation."}],"metrics":[{"cvssV2_0":{"accessComplexity":"MEDIUM","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"NONE","baseScore":7.8,"confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","vectorString":"AV:N/AC:M/Au:N/C:C/I:P/A:N","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-338","description":"CWE-338","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-06T17:33:48.282Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"name":"68797","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/68797"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a"},{"url":"http://support.oleumtech.com/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"OleumTech has created updates for both BreeZ and the gateway to mitigate\n all these vulnerabilities. These updates allow users to encrypt their \nwireless traffic with AES256. To obtain these updates, please log in to \nthe OleumTech download center (<a target=\"_blank\" rel=\"nofollow\" href=\"http://support.oleumtech.com/\">http://support.oleumtech.com/</a>&nbsp;) or contact OleumTech tech support:<p>Phone: 866-508-8586</p>\n<p>Email: <a target=\"_blank\" rel=\"nofollow\">TechSupport@OleumTech.com</a></p>"}],"value":"OleumTech has created updates for both BreeZ and the gateway to mitigate\n all these vulnerabilities. These updates allow users to encrypt their \nwireless traffic with AES256. To obtain these updates, please log in to \nthe OleumTech download center ( http://support.oleumtech.com/  ) or contact OleumTech tech support:Phone: 866-508-8586\n\n\nEmail: TechSupport@OleumTech.com"}],"source":{"advisory":"ICSA-14-202-01","discovery":"EXTERNAL"},"title":"OleumTech WIO Use of Cryptographically Weak Pseudo-Random Number Generator","x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-2360","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via packets that report a high battery voltage."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"68797","refsource":"BID","url":"http://www.securityfocus.com/bid/68797"},{"name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01","refsource":"MISC","url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-202-01"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-2362","datePublished":"2014-07-24T14:00:00.000Z","dateReserved":"2014-03-13T00:00:00.000Z","dateUpdated":"2025-10-06T17:33:48.282Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-07-24 14:55:07","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-338","NVD-CWE-Other","CWE-338 CWE-338"],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:P/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":7.8,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:P/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":7.8,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:oleumtech:sensor_wireless_i\\/o_module:-:*:*:*:*:*:*:*","matchCriteriaId":"82FA879C-B098-4A44-9036-43854ACBFD50"},{"vulnerable":true,"criteria":"cpe:2.3:h:oleumtech:wio_dh2_wireless_gateway:-:*:*:*:*:*:*:*","matchCriteriaId":"4055E1A3-F159-4B24-926C-578CE8632331"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2362","Ordinal":"1","Title":"OleumTech WIO Use of Cryptographically Weak Pseudo-Random Number","CVE":"CVE-2014-2362","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2362","Ordinal":"1","NoteData":"OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.","Type":"Description","Title":"OleumTech WIO Use of Cryptographically Weak Pseudo-Random Number"},{"CveYear":"2014","CveId":"2362","Ordinal":"2","NoteData":"2014-07-24","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2362","Ordinal":"3","NoteData":"2016-11-25","Type":"Other","Title":"Modified"}]}}}