CVE-2018-18326: High severity dnn (dotnetnuke) vulnerability
Published Jul 3, 2019
·Updated
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
Affected Software
1 affected component
dnnsoftware Dotnetnuke>=9.2<=9.2.2
Event History
Jul 3, 2019
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
Description
Frequently Asked Questions
1
What is CVE-2018-18326?
CVE-2018-18326 is a vulnerability in DNN (aka DotNetNuke) versions 9.2 through 9.2.2 that results in lower than expected entropy due to incorrect conversion of encryption key source values.
2
How does CVE-2018-18326 impact DNN (DotNetNuke)?
CVE-2018-18326 lowers the expected entropy in DNN (DotNetNuke) 9.2 - 9.2.2, which can weaken the security of encryption.
3
What is the severity of CVE-2018-18326?
CVE-2018-18326 has a severity rating of 7.5 (high).
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-18326?
The Common Weakness Enumeration (CWE) ID for CVE-2018-18326 is 331.
5
How do I fix CVE-2018-18326 in DNN (DotNetNuke)?
To fix CVE-2018-18326, users should upgrade their DNN (DotNetNuke) installations to version 9.2.3 or later.