Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crgg-fmm9-8rmq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.

In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.

EPSS

Процентиль: 47%
0.00241
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-332

Связанные уязвимости

CVSS3: 2.6
nvd
около 8 лет назад

In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.

EPSS

Процентиль: 47%
0.00241
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-332