CVE-2001-0950
Severity CVSS v4.0:
Pending analysis
Type:
CWE-331
Insufficient Entropy
Publication date:
04/12/2001
Last modified:
03/04/2025
Description
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:valicert:enterprise_validation_authority:*:*:*:*:*:*:*:* | 3.3 (including) | 4.2.1 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?l=bugtraq&m=100749428517090&w=2
- http://www.securityfocus.com/bid/3618
- http://www.securityfocus.com/bid/3620
- http://www.valicert.com/support/security_advisory_eva.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7651
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7653
- http://marc.info/?l=bugtraq&m=100749428517090&w=2
- http://www.securityfocus.com/bid/3618
- http://www.securityfocus.com/bid/3620
- http://www.valicert.com/support/security_advisory_eva.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7651
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7653