PT-2005-3917 · Securew2 · Securew2
Publicado
2005-09-27
·
Atualizado
2008-09-05
·
CVE-2005-3087
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SecureW2 version 3.0
Description
The issue concerns the use of weak random number generators, specifically
rand and srand from system time, during the generation of the pre-master secret (PMS) in the TLS implementation. This weakness makes it easier for attackers to guess the secret and decrypt sensitive data.Recommendations
For SecureW2 version 3.0, consider updating the random number generation mechanism to a more secure alternative to prevent attackers from guessing the pre-master secret. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Securew2