Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mp27-67w3-v3v9

Опубликовано: 03 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

?The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the token are generated using predictable time-based values. An attacker with this knowledge could successfully brute force the token and authenticate themselves.

?The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the token are generated using predictable time-based values. An attacker with this knowledge could successfully brute force the token and authenticate themselves.

EPSS

Процентиль: 31%
0.00121
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 5.9
nvd
больше 2 лет назад

​The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the token are generated using predictable time-based values. An attacker with this knowledge could successfully brute force the token and authenticate themselves.

EPSS

Процентиль: 31%
0.00121
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-331