CVE Database
/

CVE-2023-26154

Back to search

CVE-2023-26154

Published: Dec 6, 2023

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

5.9

MEDIUM

Description

Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the package github.com/pubnub/go; versions of the package github.com/pubnub/go/v7 before 7.2.0; versions of the package pubnub before 7.3.0; versions of the package pubnub/pubnub before 6.1.0; versions of the package pubnub before 5.3.0; versions of the package pubnub before 0.4.0; versions of the package pubnub/c-core before 4.5.0; versions of the package com.pubnub:pubnub-kotlin before 7.7.0; versions of the package pubnub/swift before 6.2.0; versions of the package pubnub before 5.2.0; versions of the package pubnub before 4.3.0 are vulnerable to Insufficient Entropy via the getKey function, due to inefficient implementation of the AES-256-CBC cryptographic algorithm. The provided encrypt function is less secure when hex encoding and trimming are applied, leaving half of the bits in the key always the same for every encoded message or file. **Note:** In order to exploit this vulnerability, the attacker needs to invest resources in preparing the attack and brute-force the encryption.

VendorProductVersions

n/a

pubnub

affected
0 - < 7.4.0

n/a

com.pubnub:pubnub

affected
0 - < *

n/a

Pubnub

affected
0 - < 6.19.0

n/a

github.com/pubnub/go

affected
0 - < *

n/a

github.com/pubnub/go/v7

affected
0 - < 7.2.0

n/a

pubnub

affected
0 - < 7.3.0

n/a

pubnub/pubnub

affected
0 - < 6.1.0

n/a

pubnub

affected
0 - < 5.3.0

n/a

pubnub

affected
0 - < 0.4.0

n/a

pubnub/c-core

affected
0 - < 4.5.0

n/a

com.pubnub:pubnub-kotlin

affected
0 - < 7.7.0

n/a

pubnub/swift

affected
0 - < 6.2.0

n/a

PubNub

affected
0 - < 5.2.0

n/a

pubnub

affected
0 - < 4.3.0

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now