CVE-2006-1117
nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only…
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- ncipher/dse200 document sealing engine · ncipher/ncore · ncipher/nforce · ncipher/securedb · ncipher/time source master clock · ncipher/nethsm · ncipher/nshield · ncipher/payshield
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19137Patch, Vendor Advisory
- http://securitytracker.com/id?1015718Patch, Vendor Advisory
- http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_securityPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/427151/100/0/threaded
- http://www.securityfocus.com/bid/17012Patch
- http://www.vupen.com/english/advisories/2006/0862
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25063
- http://secunia.com/advisories/19137Patch, Vendor Advisory
- http://securitytracker.com/id?1015718Patch, Vendor Advisory
- http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_securityPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/427151/100/0/threaded
- http://www.securityfocus.com/bid/17012Patch
- http://www.vupen.com/english/advisories/2006/0862
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25063
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.