CVE-2015-7923: Westermo Weos
Critical severity, CVSS 9.0. EPSS: 1.2% chance of exploitation in the next 30 days.
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.
Affected products
- Westermo Weos: version 4.18.0 only
Published 2016-01-30. Last modified 2026-06-17.