ZeroHour

CVE-2017-12871

CVSS 3.0
5.9 medium
EPSS
<1%p40
Published
()
Modified
Description

The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

Vendors
simplesamlphp
Products
simplesamlphp
Weakness
CWE-326
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.