VulnerabilityModified
CVE-2014-3503
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.
MEDIUM 5.0EPSS 5.97%
Does this matter?
Lower severity and a low EPSS score (5.97%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 5.97% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- apache/syncope
- Source
- secalert@redhat.com
References
- http://packetstormsecurity.com/files/127375/Apache-Syncope-Insecure-Password-Generation.html
- http://syncope.apache.org/security.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/532669/100/0/threaded
- http://www.securityfocus.com/bid/68431
- http://packetstormsecurity.com/files/127375/Apache-Syncope-Insecure-Password-Generation.html
- http://syncope.apache.org/security.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/532669/100/0/threaded
- http://www.securityfocus.com/bid/68431
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.