CVE-2013-0137

critical
Published 2013-06-30 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 contains a known SSH private key, which makes it easier for remote attackers to obtain root access, and spoof alerts, via an SSH session.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — http://www.monroe-electronics.com/MONROE_ELECTRONICS_PDF/130604-Monroe-Security-PR.pdf

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — http://www.digitalalertsystems.com/pdf/130604-Monroe-Security-PR.pdf

References

CWEs

CWE-310

Verify integrity in audit chain (admin only). AS-IS.