First published: Thu Mar 09 2006(Updated: )
The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrity checks and modify messages without being detected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nCipher nCore | =2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.