Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-4295

EPSS 0.37% · P59
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-4295

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which makes it easier for remote attackers to obtain sensitive information by predicting a key and then using it to decrypt sniffed network traffic.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sun Ray Server Software DTU安装设备驱动程序敏感信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sun Ray Server Software 4.0和4.1不能在每个Sun Ray 1, 1g, 100,和150 DTU安装设备驱动程序中的固件中产生一个惟一的DSA个人密钥,更易于远程攻击者可以借助预测一个钥匙来获得敏感信息并用它破译网络交通。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-4295

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-4295

Please Login to view more intelligence information

Same Patch Batch · n/a · 2009-12-11 · 6 CVEs total

CVE-2009-4296Drupal Taxonomy Timer模块SQL注入漏洞
CVE-2009-3027Symantec Veritas产品VRTSweb组件远程代码执行漏洞
CVE-2009-4124Ruby-Lang ’rb_str_justify()’ 缓冲区错误漏洞
CVE-2009-4135GNU coreutils 'dist-check.mk'distcheck规则安全权限漏洞
CVE-2009-4294Sun Ray Server认证管理器远程命令执行漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-4295

No comments yet


Leave a comment