Missing Encryption of Sensitive Data
CVE-2014-2379
Summary
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to interfere with traffic control by replaying transmissions on a wireless network.
- HIGH
- ADJACENT_NETWORK
- NONE
- PARTIAL
- PARTIAL
- PARTIAL
CWE-311 - Missing Encryption of Sensitive Data
The software does not encrypt sensitive or critical information before storage or transmission.
References
Advisory Timeline
- Published