CVE-2015-10148 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: April 3, 2026
Hirschmann HiLCOS - Weak Cryptography
Published: April 3, 2026Updated: April 3, 2026Remote Exploitable
Overview
Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 < 8.80 and OpenBAT < 9.10 contain a weak cryptography vulnerability caused by identical default SSH and SSL keys that cannot be changed, letting unauthenticated remote attackers perform man-in-the-middle attacks and intercept encrypted management communications, exploit requires use of default keys.
Severity & Score
Severity: High
CVSS Score: 8.2
Impact
Unauthenticated attackers can intercept and decrypt management communications, impersonate devices, and expose sensitive information.
Mitigation
Update to versions 8.80 or later for BAT300, BAT54 and WLC, and 9.10 or later for OpenBAT or latest available versions.
References
Related Resources
Details
- CVE ID
- CVE-2015-10148
- Severity
- High
- CVSS Score
- 8.2
- Type
- weak_cryptography
- Status
- new
CWE
- CWE-321
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N