// For flags

CVE-2014-2319

PowerArchiver Insecure PKZIP Encryption

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which makes it easier for context-dependent attackers to obtain sensitive information via a known-plaintext attack.

La funcionalidad Encrypt Files en ConeXware PowerArchiver anterior a 14.02.05 utiliza codificación legada de ZIP incluso si la selección AES 256-bit es elegida, lo que facilita a atacantes dependientes de contexto obtener información sensible a través de un ataque de texto plano conocido.

PowerArchiver version 14.02.03 creates files with an insecure encryption method even if the user selects a (secure) AES encryption in the GUI. If a user clicks on the "Encrypt Files" and selects "AES 256-bit" for encryption, the outcoming file will not be AES-encrypted. It will instead use the legacy PKZIP encryption, which uses a broken encryption algorithm.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-03-10 CVE Reserved
  • 2014-03-13 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-310: Cryptographic Issues
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Powerarchiver
Search vendor "Powerarchiver"
Powerarchiver
Search vendor "Powerarchiver" for product "Powerarchiver"
<= 14.02.03
Search vendor "Powerarchiver" for product "Powerarchiver" and version " <= 14.02.03"
-
Affected
Powerarchiver
Search vendor "Powerarchiver"
Powerarchiver
Search vendor "Powerarchiver" for product "Powerarchiver"
14.00
Search vendor "Powerarchiver" for product "Powerarchiver" and version "14.00"
-
Affected
Powerarchiver
Search vendor "Powerarchiver"
Powerarchiver
Search vendor "Powerarchiver" for product "Powerarchiver"
14.01
Search vendor "Powerarchiver" for product "Powerarchiver" and version "14.01"
-
Affected
Powerarchiver
Search vendor "Powerarchiver"
Powerarchiver
Search vendor "Powerarchiver" for product "Powerarchiver"
14.02
Search vendor "Powerarchiver" for product "Powerarchiver" and version "14.02"
-
Affected