CVE-2017-12871
—CVSS 3.0
5.9 medium
EPSS
<1%p40
Published
()
Modified
Description
The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).
- Vendors
- simplesamlphp
- Products
- simplesamlphp
- Weakness
- CWE-326
- Vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.