"value":"The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging unspecified \"security concerns,\" aka the ESA-2013-068 issue. NOTE: this issue has been SPLIT from CVE-2007-6755 because the vendor announcement did not state a specific technical rationale for a change in the algorithm; thus, CVE cannot reach a conclusion that a CVE-2007-6755 concern was the reason, or one of the reasons, for this change."
},
{
"lang":"es",
"value":"La configuraci\u00f3n por defecto de EMC RSA BSAFE Toolkits y RSA Data Protection Manager (DPM) 20130918 utiliza el algoritmo Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG), lo que facilita a atacantes dependientes de contexto anular mecanismos de protecci\u00f3n criptogr\u00e1fica mediante el aprovechamiento de 'temas de seguridad' no especificados, tambi\u00e9n conocido como el problema ESA-2013-068. NOTA: este problema ha sido dividido (SPLIT) de CVE-2007-6755 porque la declaraci\u00f3n del proveedor no ofreci\u00f3 un razonamiento t\u00e9cnico especifico para un cambio en el algoritmo; por lo tanto, CVE no puede llegar a una conclusi\u00f3n que un tema de CVE-2007-6755 fue la raz\u00f3n, o una de las razones, para este cambio."
"evaluatorComment":"As with CVE-2007-6755 this vulnerability has been scored with the assumption the relationship between P and Q is known to the attacker. Please see CVE-2007-6755 [link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6755] more information."