Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-943v-gjf3-5w35

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.

NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.

EPSS

Процентиль: 65%
0.01198
Низкий

Связанные уязвимости

nvd
больше 21 года назад

NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.

EPSS

Процентиль: 65%
0.01198
Низкий