Skip to main content

Missing Encryption of Sensitive Data

CVE-2014-2379

Severity Medium
Score 4.3/10

Summary

Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to interfere with traffic control by replaying transmissions on a wireless network.

  • HIGH
  • ADJACENT_NETWORK
  • NONE
  • PARTIAL
  • PARTIAL
  • PARTIAL

CWE-311 - Missing Encryption of Sensitive Data

The software does not encrypt sensitive or critical information before storage or transmission.

References

Advisory Timeline

  • Published