PT-2005-3917 · Securew2 · Securew2
Published
2005-09-27
·
Updated
2008-09-05
·
CVE-2005-3087
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SecureW2 version 3.0
Description
The issue concerns the use of weak random number generators, specifically
rand and srand from system time, during the generation of the pre-master secret (PMS) in the TLS implementation. This weakness makes it easier for attackers to guess the secret and decrypt sensitive data.Recommendations
For SecureW2 version 3.0, consider updating the random number generation mechanism to a more secure alternative to prevent attackers from guessing the pre-master secret. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Securew2