Release date:
Updated on:
Affected Systems:
Innominate mGuard 7.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-3006
MGuard is a product line of Innominate, including firewall and VPN network security devices.
Earlier than Innominate mGuard 7.5.0 used weak entropy when generating HTTPS and SSH keys. Through man-in-the-middle attacks, attackers can speculate on keys and leak sensitive information.
<* Source: Nadia Heninger
J. Alex Halderman
Link: http://secunia.com/advisories/49632/
Http://www.innominate.com/data/downloads/software/innominate_security_advisory_20120614_001.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Innominate
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.innominate.com/data/downloads/software/