PT-2020-5865 · Php+9 · Php+9

Published

2020-04-27

·

Updated

2025-08-11

·

CVE-2020-7069

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: PHP versions 7.2.x below 7.2.34 PHP versions 7.3.x below 7.3.23 PHP versions 7.4.x below 7.4.11
Description: The issue is related to the openssl encrypt() function in PHP when used with AES-CCM mode and a 12-byte initialization vector (IV). Only the first 7 bytes of the IV are actually used, which can lead to decreased security and incorrect encryption data. This can allow a remote attacker to access and compromise confidential data.
Recommendations: For PHP versions 7.2.x below 7.2.34, update to version 7.2.34 or later. For PHP versions 7.3.x below 7.3.23, update to version 7.3.23 or later. For PHP versions 7.4.x below 7.4.11, update to version 7.4.11 or later. As a temporary workaround, consider avoiding the use of the openssl encrypt() function with AES-CCM mode and 12-byte IV until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.

Exploit

Fix

Inadequate Encryption Strength

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4213
ALT-PU-2020-2960
ALT-PU-2020-3009
ALT-PU-2021-3079
BDU:2021-01912
BIT-LIBPHP-2020-7069
BIT-PHP-2020-7069
BIT-PHP-MIN-2020-7069
CESA-2021_4213
CVE-2020-7069
DSA-4856-1
OESA-2021-1056
OESA-2021-1065
OPENSUSE-SU-2020:1703-1
OPENSUSE-SU-2020:1767-1
OPENSUSE-SU-2020_1703-1
OPENSUSE-SU-2020_1767-1
OPENSUSE-SU-2022_4067-1
OPENSUSE-SU-2022_4069-1
RHSA-2021:2992
RHSA-2021:4213
RHSA-2021_4213
RLSA-2021:4213
SUSE-SU-2020:2896-1
SUSE-SU-2020:2941-1
SUSE-SU-2020:2943-1
SUSE-SU-2020:2997-1
SUSE-SU-2020_2896-1
SUSE-SU-2020_2941-1
SUSE-SU-2020_2943-1
SUSE-SU-2020_2997-1
SUSE-SU-2022:4067-1
SUSE-SU-2022:4068-1
SUSE-SU-2022:4069-1
USN-4583-1
USN-4583-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Php
Red Hat
Rocky Linux
Suse
Ubuntu