VulnerabilityModified
CVE-2013-7373
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
HIGH 7.5EPSS 1.14%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- google/android
- Source
- cve@mitre.org
References
- http://android-developers.blogspot.com.au/2013/08/some-securerandom-thoughts.html
- http://emboss.github.io/blog/2013/08/21/openssl-prng-is-not-really-fork-safe/
- http://marc.info/?l=openssl-dev&m=130289811108150&w=2
- http://marc.info/?l=openssl-dev&m=130298304903422&w=2
- http://www.reddit.com/r/Android/comments/1k6f03/due_to_a_serious_encryptionrng_flaw_in_android/cblvum5
- http://android-developers.blogspot.com.au/2013/08/some-securerandom-thoughts.html
- http://emboss.github.io/blog/2013/08/21/openssl-prng-is-not-really-fork-safe/
- http://marc.info/?l=openssl-dev&m=130289811108150&w=2
- http://marc.info/?l=openssl-dev&m=130298304903422&w=2
- http://www.reddit.com/r/Android/comments/1k6f03/due_to_a_serious_encryptionrng_flaw_in_android/cblvum5
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.