Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qr7p-mcrr-3xxp

Опубликовано: 22 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key is derived from the string "(c)2007 UCI Software GmbH B.Boll" (without quotes). The key is both static and hardcoded. With access to messages, this results in message decryption and encryption by an attacker. Thus, it enables passive and active man-in-the-middle attacks.

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key is derived from the string "(c)2007 UCI Software GmbH B.Boll" (without quotes). The key is both static and hardcoded. With access to messages, this results in message decryption and encryption by an attacker. Thus, it enables passive and active man-in-the-middle attacks.

EPSS

Процентиль: 6%
0.00023
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key is derived from the string "(c)2007 UCI Software GmbH B.Boll" (without quotes). The key is both static and hardcoded. With access to messages, this results in message decryption and encryption by an attacker. Thus, it enables passive and active man-in-the-middle attacks.

EPSS

Процентиль: 6%
0.00023
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-798