Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-45165

Опубликовано: 22 авг. 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key is derived from the string "(c)2007 UCI Software GmbH B.Boll" (without quotes). The key is both static and hardcoded. With access to messages, this results in message decryption and encryption by an attacker. Thus, it enables passive and active man-in-the-middle attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:uci:idol2:*:*:*:*:*:*:*:*
Версия до 2.12 (включая)

EPSS

Процентиль: 5%
0.00023
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 5.3
github
больше 1 года назад

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key is derived from the string "(c)2007 UCI Software GmbH B.Boll" (without quotes). The key is both static and hardcoded. With access to messages, this results in message decryption and encryption by an attacker. Thus, it enables passive and active man-in-the-middle attacks.

EPSS

Процентиль: 5%
0.00023
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-798