ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1...
Vulnerability Description
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2001-0950
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7651
- http://www.securityfocus.com/bid/3620
- http://marc.info/?l=bugtraq&m=100749428517090&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7653
- http://www.valicert.com/support/security_advisory_eva.html
- http://www.securityfocus.com/bid/3618
More from valicert
View All →Affected Vendor
valicert
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.