PT-2018-11069 · Norton · Norton Identity Safe
Published
2018-08-29
·
Updated
2020-07-15
·
CVE-2018-12240
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Norton Identity Safe versions prior to 5.3.0.976
Description
The issue is related to a privilege escalation problem due to a hard-coded IV, which can increase the likelihood of encrypted data being recovered without proper credentials.
Recommendations
For versions prior to 5.3.0.976, update to version 5.3.0.976 or later to resolve the issue.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Norton Identity Safe