Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2001-0950

Опубликовано: 04 дек. 2001
Источник: nvd
CVSS3: 7.5
CVSS2: 7.5
EPSS Низкий

Описание

ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:valicert:enterprise_validation_authority:*:*:*:*:*:*:*:*
Версия от 3.3 (включая) до 4.2.1 (включая)

EPSS

Процентиль: 82%
0.01629
Низкий

7.5 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 7.5
github
почти 4 года назад

ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.

EPSS

Процентиль: 82%
0.01629
Низкий

7.5 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-331