First published: Thu Mar 09 2006(Updated: )
The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrity checks and modify messages without being detected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nCipher | =2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1116 is considered to be of medium severity, as it allows attackers to bypass integrity checks.
To fix CVE-2006-1116, upgrade the nCipher nCore API to version 2.18 or later.
CVE-2006-1116 allows attackers to modify messages undetected, which can lead to data integrity issues.
CVE-2006-1116 affects nCipher nCore version 2.17 and earlier.
Yes, CVE-2006-1116 can be exploited remotely by attackers targeting the nCipher nCore API.