Back to Database
Status published
Low
CVE-2013-6394
Percona XtraBackup before 2.1.6 uses a constant string for the...
Vulnerability Description
Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-6394
Credits & Attribution
No credits recorded in the NVD database.
References
More from percona
View All →CVE-2024-7701
Misuse of SHA256 to create an encryption key
Medium
5.1
CVE-2022-34968
An issue in the fetch_step function in Percona Server for...
High
7.5
CVE-2022-26944
Percona XtraBackup 2.4.20 unintentionally writes the command line to any...
Medium
6.5
CVE-2022-25834
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19,...
High
7.8
CVE-2020-7920
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1...
High
7.5
Affected Vendor
percona
View all reports →Affected Software
xtrabackup, opensuse
Vulnerable Versions:
0, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 13.1
Timeline
Official Publish:
December 13th, 2013
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.