// For flags

CVE-2019-3465

 

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.

Rob Richards XmlSecLibs, todas las versiones anteriores a la v3.0.3, como es usada por ejemplo mediante SimpleSAMLphp, realizó una comprobación incorrecta de las firmas criptográficas en los mensajes XML, permitiendo a un atacante autenticado suplantar a otros o elevar los privilegios por medio de la creación de un mensaje XML diseñado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-12-31 CVE Reserved
  • 2019-11-06 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-10-31 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (15)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Xmlseclibs Project
Search vendor "Xmlseclibs Project"
Xmlseclibs
Search vendor "Xmlseclibs Project" for product "Xmlseclibs"
>= 1.0.0 <= 1.4.2
Search vendor "Xmlseclibs Project" for product "Xmlseclibs" and version " >= 1.0.0 <= 1.4.2"
-
Affected
Xmlseclibs Project
Search vendor "Xmlseclibs Project"
Xmlseclibs
Search vendor "Xmlseclibs Project" for product "Xmlseclibs"
>= 2.0.0 <= 2.1.0
Search vendor "Xmlseclibs Project" for product "Xmlseclibs" and version " >= 2.0.0 <= 2.1.0"
-
Affected
Xmlseclibs Project
Search vendor "Xmlseclibs Project"
Xmlseclibs
Search vendor "Xmlseclibs Project" for product "Xmlseclibs"
>= 3.0.0 <= 3.0.3
Search vendor "Xmlseclibs Project" for product "Xmlseclibs" and version " >= 3.0.0 <= 3.0.3"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
8.0
Search vendor "Debian" for product "Debian Linux" and version "8.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
9.0
Search vendor "Debian" for product "Debian Linux" and version "9.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
10.0
Search vendor "Debian" for product "Debian Linux" and version "10.0"
-
Affected
Simplesamlphp
Search vendor "Simplesamlphp"
Simplesamlphp
Search vendor "Simplesamlphp" for product "Simplesamlphp"
<= 1.17.6
Search vendor "Simplesamlphp" for product "Simplesamlphp" and version " <= 1.17.6"
-
Affected