CVE-2019-16753
Published on: 12/04/2019 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:49 PM UTC
Certain versions of Decentralized Anonymous Payment System from Decentralized Anonymous Payment System Project contain the following vulnerability:
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations. This is a weak signature scheme design that would allow the reuse of signatures in some cases (or even the reuse of signatures, intended for one type of message, for another type). This also affects Private Instant Verified Transactions (PIVX) through 3.4.0.
- CVE-2019-16753 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Page not found - DAPS Coin | Exploit Third Party Advisory officialdapscoin.com text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Decentralized Anonymous Payment System Project | Decentralized Anonymous Payment System | All | All | All | All |
Application | Pivx | Private Instant Verified Transactions | All | All | All | All |
- cpe:2.3:a:decentralized_anonymous_payment_system_project:decentralized_anonymous_payment_system:*:*:*:*:*:*:*:*:
- cpe:2.3:a:pivx:private_instant_verified_transactions:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE