CVE-2009-1477 describes a critical vulnerability in ATEN KH1516i, KN9116 IP KVM switches, and PN9108 power-control units, where a hardcoded SSL private key is present in their HTTPS web interfaces. This flaw allows remote attackers to decrypt encrypted HTTPS sessions by extracting the key from one device and using it to intercept traffic to another. With a CVSS score of 10.0, this vulnerability is highly severe, requiring no authentication or complex attack vectors, and can lead to complete compromise of confidentiality, integrity, and availability. There is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.063CPE matchmatch criteria | cpe:2.3:h:aten:kh1516i_ip_kvm_switch:1.0.063:*:*:*:*:*:*:* | ||
1.1.104CPE matchmatch criteria | cpe:2.3:h:aten:kn9116_ip_kvm_switch:1.1.104:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:aten:pn9108_power_over_the_net:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.