Weak Encryption in Revelation by Black Hexagon
CVE-2012-2743

Currently unrated

Key Information:

Vendor
CVE Published:
27 June 2012

What is CVE-2012-2743?

The product Revelation, specifically versions 0.4.13-2 and earlier, suffers from a weakness in its encryption methodology. The software does not properly iterate through SHA hashing algorithms for AES encryption, leading to a vulnerability where attackers can exploit this flaw to guess passwords more easily via brute force techniques. This lack of iteration limits the password length to 32 characters, which helps attackers to compromise accounts by reducing the complexity of potential password combinations. The issue underscores the importance of employing robust hashing techniques to safeguard sensitive data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.