CVE-2005-0809
NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- notify technology/notifylink
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/14617
- http://www.kb.cert.org/vuls/id/581068Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/12843
- http://secunia.com/advisories/14617
- http://www.kb.cert.org/vuls/id/581068Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/12843
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.