ZeroHour

CVE-2018-5261

PoC
CVSS 3.0
8.1 high
EPSS
<1%p38
Published
()
Modified
Description

An issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryption key used for the encryption of the rest of the session, the server and client disclose sensitive information, such as the authentication credentials, to any man-in-the-middle (MiTM) listener.

Vendors
flexense
Products
diskboss
Weakness
CWE-311
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.