Impact
The Genucenter web interface exposes SNMP authentication and encryption keys in HTTP responses to users with Service or Admin roles. This allows any user with those roles to retrieve the SNMP credentials used by the system, potentially enabling impersonation of the SNMP agent or decryption of SNMP traffic. The flaw is classified as an information‑disclosure weakness (CWE‑201).
Affected Systems
All installations of Genua Genucenter running a version older than 8.0p11 are affected when accessed through the web interface by users assigned the Service or Admin role. No other configuration settings are required for exploitation.
Risk and Exploitability
Because the flaw only affects authenticated Service or Admin users accessing the web UI, the attack vector is an authenticated web‑interface request. The CVSS score of 4.3 reflects its low severity, and the EPSS score of less than 1% indicates a very low probability of automated exploitation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment