7.5

CVE-2019-7858

A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive information with an algorithm that is insufficiently resistant to brute force attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Magento ≫ Magento SwEdition open_source Version >= 2.1.0 < 2.1.18
Magento ≫ Magento SwEdition open_source Version >= 2.2.0 < 2.2.9
Magento ≫ Magento SwEdition open_source Version >= 2.3.0 < 2.3.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.496
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23
Vendor Advisory