{ "id": "CVE-2014-4193", "sourceIdentifier": "cve@mitre.org", "published": "2014-06-17T15:55:06.753", "lastModified": "2021-11-30T18:26:15.267", "vulnStatus": "Modified", "evaluatorComment": "As with CVE-2007-6755 this vulnerability has been scored with the assumption the relationship between P and Q is known to the attacker. Please see CVE-2007-6755 [link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6755] more information.", "descriptions": [ { "lang": "en", "value": "The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algorithm, which makes it easier for remote attackers to obtain plaintext from TLS sessions by requesting long nonces from a server, a different issue than CVE-2007-6755." }, { "lang": "es", "value": "La implementaci\u00f3n TLS en EMC RSA BSAFE-Java Toolkits (tambi\u00e9n conocido como Share for Java) soporta la extensi\u00f3n Extended Random durante el uso del algoritmo Dual_EC_DRBG, lo que facilita a atacantes remotos obtener texto plano de sesiones TLS mediante la solicitud de caracteres de un s\u00f3lo uso largos de un servidor, un problema diferente a CVE-2007-6755." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-310" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:dell:bsafe_share:-:*:*:*:*:*:*:*", "matchCriteriaId": "D3E53F40-415C-4793-94D3-A4F51734C199" } ] } ] } ], "references": [ { "url": "http://dualec.org/", "source": "cve@mitre.org" }, { "url": "http://dualec.org/DualECTLS.pdf", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/68191", "source": "cve@mitre.org" } ] }