Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2012-4898 Details
Description
Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.us-cert.gov/control_systems/pdf/ICSA-12-297-01.pdf | CVE | US Government Resource |
| https://www.cisa.gov/news-events/ics-advisories/icsa-12-297-01 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-310 | Cryptographic Issues | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tropos mesh os | <= 7.9.1 |
CPE
Remediation
| |
| tropos 1310 distrubution automation mesh router | All versions |
CPE
Remediation
| |
| tropos 1410 mesh router | All versions |
CPE
Remediation
| |
| tropos 1410 wireless mesh router | All versions |
CPE
Remediation
| |
| tropos 3310 indoor mesh router | All versions |
CPE
Remediation
| |
| tropos 3320 indoor mesh router | All versions |
CPE
Remediation
| |
| tropos 4310 mobile mesh router | All versions |
CPE
Remediation
| |
| tropos 6310 mesh router | All versions |
CPE
Remediation
| |
| tropos 6320 mesh router | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | Status Change | [email protected] |
| Jul 9, 2025 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 19, 2012 | Initial Analysis | [email protected] |