Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-1117


nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.


Published

2006-03-09T13:06:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.6 (LOW)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

4.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ncipher dse200_document_sealing_engine * Yes
Application ncipher ncore * Yes
Application ncipher nforce * Yes
Application ncipher securedb * Yes
Application ncipher time_source_master_clock * Yes
Hardware ncipher nethsm 2.0 Yes
Hardware ncipher nethsm 2.1 Yes
Hardware ncipher nethsm 2.1.12_cam5 Yes
Hardware ncipher nshield * Yes
Hardware ncipher payshield * Yes

References