Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-1472

EPSS 0.18% · P40
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-1472

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Java client program for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 has a hardcoded AES encryption key, which makes it easier for man-in-the-middle attackers to (1) execute arbitrary Java code, or (2) gain access to machines connected to the switch, by hijacking a session.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
ATEN IP KVM交换机Java客户端任意代码执行漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IP KVM是台湾宏正自动科技成的系列交换机设备。 IP KVM交换机与客户端机器之间的连接所使用的加密方式存在多个漏洞,远程攻击者可以破解加密并扮演为其他用户执行恶意操作。Java客户端任意代码执行,Java客户端程序在9002端口连接到kvm交换机然后下载并运行新的Java类。这个连接是使用AES加密的,但在客户端程序中硬编码了加密密钥。扮作中间人的攻击者可以注入其他的Java类,导致在客户端机器上执行任意Java代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-1472

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-1472

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-05-27 · 5 CVEs total

CVE-2009-0588Red Hat认证系统代理组安全绕过漏洞
CVE-2009-1473ATEN IP KVM交换机密钥交换安全漏洞
CVE-2009-1474ATEN IP KVM交换机不彻底加密和不安全会话ID Cookie漏洞
CVE-2009-1477ATEN IP KVM交换机HTTPS Web接口同一SSL密钥漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-1472

No comments yet


Leave a comment