Weak Encryption in Revelation by Black Hexagon
CVE-2012-2743
Currently unrated
What is CVE-2012-2743?
The product Revelation, specifically versions 0.4.13-2 and earlier, suffers from a weakness in its encryption methodology. The software does not properly iterate through SHA hashing algorithms for AES encryption, leading to a vulnerability where attackers can exploit this flaw to guess passwords more easily via brute force techniques. This lack of iteration limits the password length to 32 characters, which helps attackers to compromise accounts by reducing the complexity of potential password combinations. The issue underscores the importance of employing robust hashing techniques to safeguard sensitive data.
