// For flags

CVE-2011-0766

 

Severity Score

7.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.

El generador de números aleatorios de la aplicación Crypto en versiones anteriores a la 2.0.2.2, y SSH anteriores a 2.0.5, como es usado en la librería Erlang/OTP ssh en versiones anteriores a la R14B03, utiliza semillas predecibles basadas en la fecha actual, lo que facilita a atacantes remotos adivinar el host DSA y las claves de sesión SSH.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-02-03 CVE Reserved
  • 2011-05-31 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-310: Cryptographic Issues
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Erlang
Search vendor "Erlang"
Crypto
Search vendor "Erlang" for product "Crypto"
<= 2.0.2.1
Search vendor "Erlang" for product "Crypto" and version " <= 2.0.2.1"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r11b-5
Search vendor "Erlang" for product "Erlang\/otp" and version "r11b-5"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r12b-5
Search vendor "Erlang" for product "Erlang\/otp" and version "r12b-5"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r13b
Search vendor "Erlang" for product "Erlang\/otp" and version "r13b"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r13b02-1
Search vendor "Erlang" for product "Erlang\/otp" and version "r13b02-1"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r13b03
Search vendor "Erlang" for product "Erlang\/otp" and version "r13b03"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r13b04
Search vendor "Erlang" for product "Erlang\/otp" and version "r13b04"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r14a
Search vendor "Erlang" for product "Erlang\/otp" and version "r14a"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r14b
Search vendor "Erlang" for product "Erlang\/otp" and version "r14b"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r14b01
Search vendor "Erlang" for product "Erlang\/otp" and version "r14b01"
-
Affected
Erlang
Search vendor "Erlang"
Erlang\/otp
Search vendor "Erlang" for product "Erlang\/otp"
r14b02
Search vendor "Erlang" for product "Erlang\/otp" and version "r14b02"
-
Affected
Ssh
Search vendor "Ssh"
Ssh
Search vendor "Ssh" for product "Ssh"
<= 2.0.4
Search vendor "Ssh" for product "Ssh" and version " <= 2.0.4"
-
Affected