SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-3075

EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local users to obtain sensitive information via calculations involving recovery of XORed data, as demonstrated by…

MEDIUM 5.0EPSS 2.06%

Does this matter?

Lower severity and a low EPSS score (2.06%). Track it; it rarely justifies an emergency change on its own.

Description

EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local users to obtain sensitive information via calculations involving recovery of XORed data, as demonstrated by an attack on encrypted data in which the last block contains only one byte.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.06% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
arg0/encfs
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.