CVE-2012-3006 describes a critical vulnerability in various Innominate mGuard appliances (Smart HW, industrial RS, delta HW, PCI, blade, and EAGLE mGuard) running software versions prior to 7.5.0. The flaw stems from insufficient entropy in private key generation, making it susceptible to prediction. This allows authenticated man-in-the-middle attackers to spoof HTTPS or SSH servers, leading to a complete compromise of confidentiality, integrity, and availability. While rated with a CVSS score of 7.1 (High) and a FAUCET Risk Score of 44/100, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.5.0CPE matchmatch criteria | cpe:2.3:o:innominate:mguard_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.