PT-2020-14859 · Kee Vault · Kee Vault Keepassrpc
Georg Merzdovnik
+2
·
Published
2020-08-03
·
Updated
2020-08-07
·
CVE-2020-16271
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Kee Vault KeePassRPC versions prior to 1.12.0
Description
The issue concerns the SRP-6a implementation, which generates insufficiently random numbers. This allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.
Recommendations
For versions prior to 1.12.0, update to version 1.12.0 or later to resolve the issue.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kee Vault Keepassrpc