An insufficient entropy vulnerability caused by the...
Moderate severity
Unreviewed
Published
Sep 21, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Sep 20, 2022
Published to the GitHub Advisory Database
Sep 21, 2022
Last updated
Jan 31, 2023
An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versions prior to V2.70. This vulnerability could allow an unauthenticated attacker to retrieve a private key by factoring the RSA modulus N in the certificate of the web administration interface.
References