By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encrypted traffic through an HTTPS connection.
Solution:
Workaround:
The product uses a hard-coded, unchangeable cryptographic key.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-005-03 | us government resource third party advisory mitigation |
https://www.gegridsolutions.com/app/DownloadFile.aspx?prod=RT430&type=21&file=5 | permissions required |