CVE-2020-16271: Critical severity keepass vulnerability
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-16271?
CVE-2020-16271 is a vulnerability in the SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.
How severe is CVE-2020-16271?
CVE-2020-16271 has a severity rating of 9.1 (critical).
Which software versions are affected by CVE-2020-16271?
CVE-2020-16271 affects Kee Vault KeePassRPC versions up to exclusive 1.12.0.
How can remote attackers exploit CVE-2020-16271?
Remote attackers can exploit CVE-2020-16271 by leveraging the insufficiently random numbers generated by the SRP-6a implementation in Kee Vault KeePassRPC, allowing them to read and modify data in the KeePass database via a WebSocket connection.
Where can I find more information about CVE-2020-16271?
You can find more information about CVE-2020-16271 at the following references: [1](https://danzinger.wien/exploiting-keepassrpc/) [2](https://forum.kee.pm/t/a-critical-security-update-for-keepassrpc-is-available/3040)