CVE-2018-15812: High severity dnn (dotnetnuke) vulnerability
Published Jul 3, 2019
·Updated
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
Affected Software
1 affected component
dnnsoftware Dotnetnuke>=9.2<=9.2.1
Event History
Jul 3, 2019
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-15812?
CVE-2018-15812 has a medium severity rating due to its impact on encryption key generation.
2
How do I fix CVE-2018-15812?
To fix CVE-2018-15812, upgrade to DNN version 9.3 or higher to ensure proper encryption key handling.
3
What versions of DNN are affected by CVE-2018-15812?
DNN versions 9.2 through 9.2.1 are affected by CVE-2018-15812.
4
Can CVE-2018-15812 lead to remote code execution?
CVE-2018-15812 could potentially contribute to a scenario allowing remote code execution due to improper handling of encryption.
5
Is there a workaround for CVE-2018-15812?
There are no known effective workarounds for CVE-2018-15812, so upgrading is highly recommended.