iStar Ultra / IP-ACM Boards Fixed AES Key

Discussion in 'News Aggregator' started by Packet Storm, 20 Dec 2017.

  1. Packet Storm

    Packet Storm Guest

    Vulnerabilities were identified in the iStar Ultra and IP-ACM boards offered by Software House. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the fixed IV, leading to replay attacks of entire messages. There is no authentication of messages beyond the use of the fixed AES key, so message forgery is also possible.

    Continue reading...
     

Share This Page

Loading...