CVE-2017-9645

MEDIUM

Mirion Technologies - Info Disclosure

Title source: llm
STIX 2.1

Description

An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (including Solar PWR Package), DRM and RDS Based Boundary Monitors, External Transmitters, Telepole II, and MESH Repeater (Telemetry Enabled Devices). Decryption of data is possible at the hardware level.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100001
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-208-02

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 14.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-326
Status published
Products (9)
mirion/dmc_3000_transmitter_firmware
mirion/drm-1\/2_firmware
mirion/drm-2_firmware
mirion/ipam_transmitter_f\/dmc_2000_firmware
mirion/rds-31_firmware
mirion/rds-31_itx_firmware
mirion/telepole_2_firmware
mirion/wrm2_firmware
n/a/Mirion Technologies Telemetry Enabled Devices Mirion Technologies Telemetry Enabled Devices
Published Sep 20, 2017
Tracked Since Feb 18, 2026