PT-2020-8471 · Unknown+1 · Aes Encryption Project+1

Heine Deelstra

·

Published

2020-12-31

·

Updated

2021-01-12

·

CVE-2017-20001

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: AES encryption project versions 7.x through 8.x
Description: The AES encryption project for Drupal does not sufficiently prevent attackers from decrypting data. This issue is not covered by Drupal's security advisory policy.
Recommendations: For versions 7.x through 8.x, update to a version that includes the necessary security patches to prevent data decryption by attackers.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20001

Affected Products

Aes Encryption Project
Drupal