Description
The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role.
Published: 2026-07-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Genucenter web interface exposes SNMP authentication and encryption keys in HTTP responses to users with Service or Admin roles. This allows any user with those roles to retrieve the SNMP credentials used by the system, potentially enabling impersonation of the SNMP agent or decryption of SNMP traffic. The flaw is classified as an information‑disclosure weakness (CWE‑201).

Affected Systems

All installations of Genua Genucenter running a version older than 8.0p11 are affected when accessed through the web interface by users assigned the Service or Admin role. No other configuration settings are required for exploitation.

Risk and Exploitability

Because the flaw only affects authenticated Service or Admin users accessing the web UI, the attack vector is an authenticated web‑interface request. The CVSS score of 4.3 reflects its low severity, and the EPSS score of less than 1% indicates a very low probability of automated exploitation. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 1, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Genucenter to version 8.0p11 or later to remove the SNMP key disclosure.
  • Restrict the Service and Admin roles to trusted personnel and, if possible, limit access to the web interface from trusted network segments.
  • Rotate SNMP authentication and encryption keys regularly and monitor SNMP traffic for signs of unauthorized decryption or impersonation.

Generated by OpenCVE AI on August 1, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Genua
Genua genucenter
Vendors & Products Genua
Genua genucenter

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role.
Title Genucenter Disclosure of SNMP Credentials
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Genua Genucenter
cve-icon MITRE

Status: PUBLISHED

Assigner: sba-research

Published:

Updated: 2026-07-01T17:47:08.068Z

Reserved: 2026-06-24T15:07:32.597Z

Link: CVE-2026-13211

cve-icon Vulnrichment

Updated: 2026-07-01T17:46:51.856Z

cve-icon NVD

Status : Deferred

Published: 2026-07-01T17:16:19.740

Modified: 2026-07-02T18:45:21.210

Link: CVE-2026-13211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T23:15:03Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data