7.5
CVE-2022-26083
- EPSS 0.03%
- Published 14.02.2025 21:15:11
- Last modified 02.09.2025 15:35:44
- Source secure@intel.com
- Teams watchlist Login
- Open Login
Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.
Data is provided by the National Vulnerability Database (NVD)
Intel ≫ Integrated Performance Primitives Cryptography Version < 2021.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.067 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
secure@intel.com | 7.5 | 1.1 | 5.8 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
|
CWE-1204 Generation of Weak Initialization Vector (IV)
The product uses a cryptographic primitive that uses an Initialization Vector (IV), but the product does not generate IVs that are sufficiently unpredictable or unique according to the expected cryptographic requirements for that primitive.