Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-949r-2wph-553m

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.

ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.

EPSS

Процентиль: 81%
0.01629
Низкий

7.5 High

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 7.5
nvd
около 24 лет назад

ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.

EPSS

Процентиль: 81%
0.01629
Низкий

7.5 High

CVSS3

Дефекты

CWE-331