Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-46894

Опубликовано: 09 нояб. 2023
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.

In certain circumstances, esptool was found to use a weak cryptographic algorithm. An attacker can exploit weak or outdated encryption algorithms to expose confidential information.

Отчет

Esptool has migrated to stronger encryption algorithms, but continues to support AES ECB when necessary to maintain compatibility with older chip revisions.

Дополнительная информация

Статус:

Low
Дефект:
CWE-326
https://bugzilla.redhat.com/show_bug.cgi?id=2248982esptool: inadequate encryption strength

EPSS

Процентиль: 40%
0.0048
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.

CVSS3: 7.5
nvd
почти 3 года назад

An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.

CVSS3: 7.5
debian
почти 3 года назад

An issue discovered in esptool 4.6.2 allows attackers to view sensitiv ...

CVSS3: 7.5
github
почти 3 года назад

esptool allows attackers to view sensitive information via weak cryptographic algorithm

EPSS

Процентиль: 40%
0.0048
Низкий

3.3 Low

CVSS3