CVE-2001-0950
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.59% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-331
- Affected
- valicert/enterprise validation authority
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=100749428517090&w=2Exploit, Mailing List
- http://www.securityfocus.com/bid/3618Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/3620Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.valicert.com/support/security_advisory_eva.htmlBroken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7651Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7653Third Party Advisory, VDB Entry
- http://marc.info/?l=bugtraq&m=100749428517090&w=2Exploit, Mailing List
- http://www.securityfocus.com/bid/3618Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/3620Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.valicert.com/support/security_advisory_eva.htmlBroken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7651Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7653Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.