2.6
CWE
NVD-CWE-Other
Advisory Published
Updated

CVE-2006-1117

First published: Thu Mar 09 2006(Updated: )

nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Ncipher Dse200 Document Sealing Engine
nCipher
nCipher
nCipher
Ncipher Time Source Master Clock
nCipher NetHSM=2.0
nCipher NetHSM=2.1
nCipher NetHSM=2.1.12_cam5
nCipher
nCipher payShield SPP library

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2006-1117?

    CVE-2006-1117 is classified with a high severity due to the presence of testing options in the firmware that could introduce significant security risks.

  • How do I fix CVE-2006-1117?

    To fix CVE-2006-1117, update the firmware to version V10 or later that removes the insecure testing options.

  • What products are affected by CVE-2006-1117?

    CVE-2006-1117 affects various nCipher products, including nShield, nForce, netHSM, payShield, SecureDB, DSE200 Document Sealing Engine, and Time Source Master Clock.

  • Is CVE-2006-1117 still a concern for organizations using affected products?

    Yes, CVE-2006-1117 remains a concern due to the potential exploitation of testing features in production environments.

  • Are there any workarounds for CVE-2006-1117?

    The best workaround for CVE-2006-1117 is to ensure affected devices are updated to secure firmware versions and to limit exposure of these devices to untrusted networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203