CVE-2013-7372 describes a vulnerability in the SecureRandom implementation of Apache Harmony, specifically in the engineNextBytes function, affecting Android versions prior to 4.4 and other products utilizing Apache Harmony through 6.0M3. When a user-provided seed is absent, an incorrect offset value leads to predictable pseudo-random number generation (PRNG). This flaw has a CVSS score of 5.0 (Medium) with a network attack vector and low attack complexity, allowing attackers to more easily defeat cryptographic protections, as demonstrated by its exploitation against Bitcoin wallet applications in August 2013. Despite its historical exploitation, there is no current evidence of active exploitation, publicly available exploit code in Metasploit, Nuclei, or ExploitDB, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0CPE matchmatch criteria | cpe:2.3:a:apache:harmony:*:m3:*:*:*:*:*:* | ||
<= 4.3.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.