SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-7252

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.

MEDIUM 5.0EPSS 2.15%

Does this matter?

Lower severity and a low EPSS score (2.15%). Track it; it rarely justifies an emergency change on its own.

Description

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.15% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
kde/kde applications
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.