HMAC Key Vulnerability in HAProxy by HAProxy Technologies
CVE-2019-11323

5.9MEDIUM

Key Information:

Vendor

Haproxy

Status
Vendor
CVE Published:
9 May 2019

What is CVE-2019-11323?

HAProxy versions prior to 1.9.7 exhibit a vulnerability that occurs during the reload process with rotated keys. This flaw results in the use of uninitialized and highly predictable HMAC keys, compromising the integrity of secure communications. The issue is linked to an error in the ssl_sock.h file, which can lead to potentially exploitable scenarios for attackers.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.