Unrated severityNVD Advisory· Published Jan 17, 2015· Updated May 6, 2026
CVE-2014-5419
CVE-2014-5419
Description
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different customers' installations, which makes it easier for remote attackers to obtain the cleartext content of network traffic by reading this key from a firmware image and then sniffing the network.
Affected products
16- GE/Multilink ML800/1200/1600/2400v5Range: 0
- GE/ML810/3000/3100 series switchv5Range: 0
- cpe:2.3:h:ge:multilink_ml3000:*:*:*:*:*:*:*:*
- cpe:2.3:h:ge:multilink_ml810:-:*:*:*:*:*:*:*
- cpe:2.3:h:ge:multilink_ml1600:-:*:*:*:*:*:*:*
- cpe:2.3:h:ge:multilink_ml3100:*:*:*:*:*:*:*:*
- cpe:2.3:h:ge:multilink_ml800:-:*:*:*:*:*:*:*
- cpe:2.3:h:ge:multilink_ml2400:-:*:*:*:*:*:*:*
- cpe:2.3:h:ge:multilink_ml1200:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.gedigitalenergy.com/products/support/multilink/MLSB1214.pdfnvdVendor Advisory
- ics-cert.us-cert.gov/advisories/ICSA-15-013-04nvdThird Party AdvisoryUS Government Resource
- github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-013-04a.jsonnvd
- www.cisa.gov/news-events/ics-advisories/icsa-15-013-04anvd
News mentions
0No linked articles in our index yet.