VulnerabilityModified
CVE-2006-2711
Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages.
MEDIUM 5.0EPSS 1.93%
Does this matter?
Lower severity and a low EPSS score (1.93%). Track it; it rarely justifies an emergency change on its own.
Description
Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- secure elements/class 5 enterprise vulnerability management
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/20377
- http://securitytracker.com/id?1016184
- http://www.kb.cert.org/vuls/id/346377Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/WDON-6QAQN6
- http://www.vupen.com/english/advisories/2006/2068
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26740
- http://secunia.com/advisories/20377
- http://securitytracker.com/id?1016184
- http://www.kb.cert.org/vuls/id/346377Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/WDON-6QAQN6
- http://www.vupen.com/english/advisories/2006/2068
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26740
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.