PT-2023-10325 · Enigma · Enigmax
Published
2023-01-02
·
Updated
2024-05-17
·
CVE-2016-15006
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
enigmaX versions prior to 2.3
Description
A problematic issue has been found in the Scrambling Table Handler component, specifically affecting the
getSeed function of the main.c file. This leads to a predictable seed in the pseudo-random number generator (prng), which can be exploited remotely. The complexity of an attack is rather high, and the exploitation is known to be difficult.Recommendations
For versions prior to 2.3, upgrade to version 2.3 to address this issue. As a temporary workaround, consider restricting access to the
getSeed function of the Scrambling Table Handler component until the upgrade is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Enigmax