SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-5386

The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection…

MEDIUM 5.0EPSS 1.52%

Does this matter?

Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.

Description

The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initialization vector.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.52% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
facebook/hiphop virtual machine
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.