7.5
CVE-2013-4104
- EPSS 0.76%
- Veröffentlicht 04.11.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 01:54:53
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cryptocat Project ≫ Cryptocat Version < 2.0.22
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.76% | 0.505 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
https://tobtu.com/decryptocat.php
https://www.openwall.com/lists/oss-security/2013/07/10/15
https://vuldb.com/?id.9436
https://www.securityfocus.com/bid/61108