Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-4192

Опубликовано: 17 июн. 2014
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only the requested byte count and not the use of cached bytes, which makes it easier for remote attackers to obtain plaintext from TLS sessions by recovering the algorithm's inner state, a different issue than CVE-2007-6755.

Комментарий

As with CVE-2007-6755 this vulnerability has been scored with the assumption the relationship between P and Q is known to the attacker. Please see CVE-2007-6755 [link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6755] more information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:bsafe_share:-:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00221
Низкий

5 Medium

CVSS2

Дефекты

CWE-310

Связанные уязвимости

github
больше 3 лет назад

The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only the requested byte count and not the use of cached bytes, which makes it easier for remote attackers to obtain plaintext from TLS sessions by recovering the algorithm's inner state, a different issue than CVE-2007-6755.

EPSS

Процентиль: 45%
0.00221
Низкий

5 Medium

CVSS2

Дефекты

CWE-310