CVE-2016-9154
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key.
Scoring
- CVSS base score
- 0.05
- EPSS probability
- 1.17%
- CWE
- CWE-332
- Published
- 2016-12-23
- Last modified
- 2026-03-14
Affected products
- n/a Desigo PX Web modules with all firmware versions < V6.00.046
Weakness type
Related vulnerabilities
- CVE-2026-3290 — Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values
- CVE-2023-20107 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
- CVE-2019-1715 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
- CVE-2017-9371 — In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of...