Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-943v-gjf3-5w35

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.

NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.

EPSS

Процентиль: 78%
0.01171
Низкий

Связанные уязвимости

nvd
почти 21 год назад

NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.

EPSS

Процентиль: 78%
0.01171
Низкий