5

CVE-2006-1116

The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrity checks and modify messages without being detected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NcipherNcore Version2.17
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.57% 0.721
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19137
Patch
Vendor Advisory
http://www.vupen.com/english/advisories/2006/0862
http://securitytracker.com/id?1015718
Patch
Vendor Advisory
http://www.ncipher.com/resources/96/sa13_cbcmac_iv_misleading_programming_interface
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/427150/100/0/threaded
http://www.securityfocus.com/bid/17011
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/25062