Description
The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role.
Published: 2026-07-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the Genucenter web interface before version 8.0p11 exposes SNMP responses to users assigned the Service or Admin role. This flaw reveals sensitive credential material, allowing those users to decrypt SNMP traffic or impersonate SNMP agents, potentially granting unauthorized access to network devices and enabling compromise of network infrastructure. The weakness is classified as an information disclosure (CWE‑201).

Affected Systems

All genua Genucenter installations running a version earlier than 8.0p11 are affected. The vulnerability applies to the web interface accessed by users assigned the Service or Admin role or configuration differences are specified.

Risk and Exploitability

With a CVSS score of 4.3 the vulnerability is Low severity. The EPSS score is < 1% and it is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Based on the description, it is inferred that exploitation requires valid credentials that grant Service or Admin level access to the web interface, making it an insider or compromised‑credential scenario. The likely attack vector is an authenticated web interface session by a user with Service or Admin privileges, which may lead to unauthorized decryption of of SNMP agents.

Generated by OpenCVE AI on July 15, 2026 at 22:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Genucenter to version 8.0p11 or later to remove the SNMP key disclosure.
  • Restrict the Service and Admin roles to a narrow group of trusted personnel or specific network segments if an update cannot be applied immediately.
  • Rotate SNMP authentication and encryption keys regularly and monitor SNMP traffic for indicators of unauthorized decryption or impersonation.

Generated by OpenCVE AI on July 15, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Genua
Genua genucenter
Vendors & Products Genua
Genua genucenter

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role.
Title Genucenter Disclosure of SNMP Credentials
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Genua Genucenter
cve-icon MITRE

Status: PUBLISHED

Assigner: sba-research

Published:

Updated: 2026-07-01T17:47:08.068Z

Reserved: 2026-06-24T15:07:32.597Z

Link: CVE-2026-13211

cve-icon Vulnrichment

Updated: 2026-07-01T17:46:51.856Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T22:15:15Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data