{"api_version":"1","generated_at":"2026-07-24T20:53:26+00:00","cve":"CVE-2006-1117","urls":{"html":"https://cve.report/CVE-2006-1117","api":"https://cve.report/api/cve/CVE-2006-1117.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1117","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1117"},"summary":{"title":"CVE-2006-1117","description":"nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-09 13:06:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://securitytracker.com/id?1015718","name":"http://securitytracker.com/id?1015718","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SecurityTracker.com Archives - nCipher nCore May Let Users Conduct Key Determination Attacks and May Fail to Detect MAC Message Modification","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25063","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25063","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/0862","name":"http://www.vupen.com/english/advisories/2006/0862","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_security","name":"http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_security","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"nCipher - SA#14: Presence of flaws in firmware security","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/19137","name":"http://secunia.com/advisories/19137","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - nCipher Products Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/427151/100/0/threaded","name":"http://www.securityfocus.com/archive/1/427151/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17012","name":"http://www.securityfocus.com/bid/17012","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"nCipher Testing Options Insecure Key Generation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1117","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1117","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ncipher","cpe5":"dse200_document_sealing_engine","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ncipher","cpe5":"ncore","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ncipher","cpe5":"nethsm","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ncipher","cpe5":"nethsm","cpe6":"2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ncipher","cpe5":"nethsm","cpe6":"2.1.12_cam5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ncipher","cpe5":"nforce","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ncipher","cpe5":"nshield","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ncipher","cpe5":"payshield","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ncipher","cpe5":"securedb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ncipher","cpe5":"time_source_master_clock","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1117","cve":"CVE-2006-1117","epss":"0.004120000","percentile":"0.614780000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:56:15.815Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-0862","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0862"},{"name":"20060309 nCipher Advisory #14: Presence of flaws in firmware security","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/427151/100/0/threaded"},{"name":"ncipher-firmware-weak-security(25063)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25063"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_security"},{"name":"1015718","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015718"},{"name":"17012","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17012"},{"name":"19137","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19137"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2006-0862","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0862"},{"name":"20060309 nCipher Advisory #14: Presence of flaws in firmware security","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/427151/100/0/threaded"},{"name":"ncipher-firmware-weak-security(25063)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25063"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_security"},{"name":"1015718","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015718"},{"name":"17012","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17012"},{"name":"19137","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19137"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1117","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-0862","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0862"},{"name":"20060309 nCipher Advisory #14: Presence of flaws in firmware security","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/427151/100/0/threaded"},{"name":"ncipher-firmware-weak-security(25063)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25063"},{"name":"http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_security","refsource":"CONFIRM","url":"http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_security"},{"name":"1015718","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015718"},{"name":"17012","refsource":"BID","url":"http://www.securityfocus.com/bid/17012"},{"name":"19137","refsource":"SECUNIA","url":"http://secunia.com/advisories/19137"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1117","datePublished":"2006-03-09T11:00:00.000Z","dateReserved":"2006-03-09T00:00:00.000Z","dateUpdated":"2024-08-07T16:56:15.815Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-09 13:06:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ncipher:dse200_document_sealing_engine:*:*:*:*:*:*:*:*","matchCriteriaId":"FD964801-9635-437D-9260-84F16619FC49"},{"vulnerable":true,"criteria":"cpe:2.3:a:ncipher:ncore:*:*:*:*:*:*:*:*","matchCriteriaId":"6FA410AE-0FC0-46DC-B89A-651DEDA51622"},{"vulnerable":true,"criteria":"cpe:2.3:a:ncipher:nforce:*:*:*:*:*:*:*:*","matchCriteriaId":"6252FF68-DB64-4BEC-86D9-A8517B0F9D64"},{"vulnerable":true,"criteria":"cpe:2.3:a:ncipher:securedb:*:*:*:*:*:*:*:*","matchCriteriaId":"6456DCB1-209C-4F63-83D0-1E73CC85F788"},{"vulnerable":true,"criteria":"cpe:2.3:a:ncipher:time_source_master_clock:*:*:*:*:*:*:*:*","matchCriteriaId":"F48A7766-4B50-4C25-8786-23DD88AFB7DB"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:ncipher:nethsm:2.0:*:*:*:*:*:*:*","matchCriteriaId":"83B802C8-58F9-4A03-BC1C-E2DA55CF1F8D"},{"vulnerable":true,"criteria":"cpe:2.3:h:ncipher:nethsm:2.1:*:*:*:*:*:*:*","matchCriteriaId":"C450BD00-9BCC-4E0F-83F9-BA5F0E293367"},{"vulnerable":true,"criteria":"cpe:2.3:h:ncipher:nethsm:2.1.12_cam5:*:*:*:*:*:*:*","matchCriteriaId":"17A5415F-6D6E-4B08-8073-7462E82520C9"},{"vulnerable":true,"criteria":"cpe:2.3:h:ncipher:nshield:*:*:*:*:*:*:*:*","matchCriteriaId":"C008CC6B-6F9A-4541-97C5-7ED7C20349C4"},{"vulnerable":true,"criteria":"cpe:2.3:h:ncipher:payshield:*:*:*:*:*:*:*:*","matchCriteriaId":"C4D0EB90-3ADD-4038-91AB-AB76C5910951"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1117","Ordinal":"1","Title":"CVE-2006-1117","CVE":"CVE-2006-1117","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1117","Ordinal":"1","NoteData":"nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.","Type":"Description","Title":"CVE-2006-1117"},{"CveYear":"2006","CveId":"1117","Ordinal":"2","NoteData":"2006-03-09","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1117","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}