VYPR
Unrated severityNVD Advisory· Published Dec 16, 2020· Updated Aug 5, 2024

CVE-2019-14482

CVE-2019-14482

Description

AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no other SSL certificate is installed, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

AdRem NetCrunch 10.6.0.4587 ships a hardcoded SSL private key, enabling attackers who obtain the key to decrypt traffic and perform man-in-the-middle attacks against installations using the default certificate.

Vulnerability

AdRem NetCrunch version 10.6.0.4587 includes a hardcoded SSL private key in its web client. When no other SSL certificate is specified during installation (i.e., when "Use OpenSSL" is chosen and "Let me specify secure OpenSSL key and certificate files" is not selected), the software uses a static, pre-generated key that is identical across all deployments. AdRem NetCrunch 11.0.0.5282 is not vulnerable; older versions remain untested but are believed to be affected [1].

Exploitation

An attacker with network access to a NetCrunch web client can first obtain the hardcoded private key from any publicly available installation or source. Armed with this key, the attacker can decrypt SSL/TLS traffic between the client and the server, or perform man-in-the-middle attacks. No authentication is required to leverage the key against other installations using the same default certificate [1].

Impact

Successful exploitation allows the attacker to defeat cryptographic protections, leading to disclosure of sensitive information transmitted over HTTPS. This can include session tokens, credentials, and monitoring data. The attacker gains the ability to read and potentially modify traffic, compromising the confidentiality and integrity of communications for the affected NetCrunch web client [1].

Mitigation

AdRem released NetCrunch version 11.0.0.5282 which is not vulnerable to this issue [1]. Users should upgrade to this version or later. Administrators can also mitigate the risk by providing their own custom SSL certificate and key during installation, bypassing the use of the hardcoded default key. No workaround is available for versions that continue to use the default certificate.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.