SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5408

A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

MEDIUM 6.5EPSS 1.59%

Does this matter?

Lower severity and a low EPSS score (1.59%). Track it; it rarely justifies an emergency change on its own.

Description

Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.59% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-329, CWE-330
Affected
pivotal software/spring security · vmware/spring security
Source
security@pivotal.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.