Encryption Key Source Vulnerability in DotNetNuke by DNN
CVE-2018-18326
7.5HIGH
What is CVE-2018-18326?
The vulnerability in DotNetNuke versions 9.2 through 9.2.2 arises from a flaw in the way encryption key source values are processed, leading to reduced entropy. This issue is a result of an incomplete fix for a previous vulnerability, CVE-2018-15812, and can potentially expose sensitive data if exploited. System administrators should ensure that they update to the latest version or implement relevant security measures to mitigate the risks associated with this vulnerability.
References
EPSS Score
76% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved