HMAC Key Vulnerability in HAProxy by HAProxy Technologies
CVE-2019-11323

5.9MEDIUM

Key Information:

Vendor

Haproxy

Status
Vendor
CVE Published:
9 May 2019

What is CVE-2019-11323?

HAProxy versions prior to 1.9.7 exhibit a vulnerability that occurs during the reload process with rotated keys. This flaw results in the use of uninitialized and highly predictable HMAC keys, compromising the integrity of secure communications. The issue is linked to an error in the ssl_sock.h file, which can lead to potentially exploitable scenarios for attackers.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.