AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-1477

HIGH · CVSS 10 EPSS 2.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-05-27 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 10.0. It may be remotely exploitable.

CVE
CVE-2009-1477
Severity
HIGH
CVSS
10
EPSS
2.15%

Original NVD Description

The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 power-control unit have a hardcoded SSL private key, which makes it easier for remote attackers to decrypt https sessions by extracting this key from their own switch and then sniffing network traffic to a switch owned by a different customer.