CVE-2006-2711
Summary
| CVE | CVE-2006-2711 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-31 22:02:00 UTC |
| Updated | 2017-07-20 01:31:00 UTC |
| Description | Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Secure Elements | Class 5 Enterprise Vulnerability Management | 2.8.0 | All | All | All |
| Application | Secure Elements | Class 5 Enterprise Vulnerability Management | 2.8.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secure Elements Information for VU#346377 | CONFIRM | www.kb.cert.org | |
| Secure Elements Class 5 AVR Message Encryption Security Issue - Advisories - Secunia | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - C5 Enterprise Vulnerability Management Bugs Let Remote Users Access the System, Execute Arbitrary Code, Monitor Communications, and Deny Service | SECTRACK | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| US-CERT Vulnerability Note VU#346377 | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.