SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-1378

PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by…

MEDIUM 4.9EPSS 0.33%

Does this matter?

Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.

Description

PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a known plaintext attack.

CVSS 2.0
4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
EPSS
0.33% probability · 26th percentile
CISA KEV
Not listed
Affected
counterpane/password safe
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.