CVE-2017-12871
published 2017-09-01CVE-2017-12871: The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the…
PriorityP428medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
0.49%
38.5th percentile
The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | simplesamlphp | < simplesamlphp 1.14.15-1 (bookworm) | simplesamlphp 1.14.15-1 (bookworm) |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.15-1 | 1.14.15-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.15-1 | 1.14.15-1 |
| simplesamlphp | simplesamlphp | >= 1.14.0 < 1.14.12 | 1.14.12 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-12871: simplesamlphp - The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x...
vendor_debian·2017·CVSS 5.9
CVE-2017-12871 [MEDIUM] CVE-2017-12871: simplesamlphp - The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x...
The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).
Scope: local
bookworm: resolved (fixed in 1.14.15-1)
bullseye: resolved (fixed in 1.14.15-1)
sid: resolved (fixed in 1.14.15-1)
OSV
SimpleSAMLphp Incorrect IV generation for encryption
osv·2022-05-17
CVE-2017-12871 [MEDIUM] SimpleSAMLphp Incorrect IV generation for encryption
SimpleSAMLphp Incorrect IV generation for encryption
The aesEncrypt method in `lib/SimpleSAML/Utils/Crypto.php` in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).
GHSA
SimpleSAMLphp Incorrect IV generation for encryption
ghsa·2022-05-17
CVE-2017-12871 [MEDIUM] CWE-326 SimpleSAMLphp Incorrect IV generation for encryption
SimpleSAMLphp Incorrect IV generation for encryption
The aesEncrypt method in `lib/SimpleSAML/Utils/Crypto.php` in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).
OSV
CVE-2017-12871: The aesEncrypt method in lib/SimpleSAML/Utils/Crypto
osv·2017-09-01·CVSS 5.9
CVE-2017-12871 [MEDIUM] CVE-2017-12871: The aesEncrypt method in lib/SimpleSAML/Utils/Crypto
The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-09-01
Published