PT-2012-4230 · Revelation · Revelation
Jan Lieskovsky
·
Published
2012-06-27
·
Updated
2017-08-29
·
CVE-2012-2743
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Revelation versions 0.4.13-2 and earlier
Description
The issue makes it easier for attackers to guess passwords via a brute force attack because it does not iterate through SHA hashing algorithms for AES encryption.
Recommendations
For versions 0.4.13-2 and earlier, update to a version that iterates through SHA hashing algorithms for AES encryption to prevent brute force attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Revelation