CVE-2014-125055 is a problematic timing discrepancy vulnerability found in the VerifyPassphrase function of the scrypt.go file within the agnivade easy-scrypt project. This flaw, classified as CWE-208, affects easy-script_project easy-script and can be remediated by upgrading to version 1.0.0. The vulnerability has a CVSS score of 5.3 (Medium), indicating a low impact on confidentiality and no impact on integrity or availability. While the attack vector is network-based, the complexity of an attack is rated as high, and exploitability is considered difficult. There is no evidence of active exploitation, and no public exploit code exists in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community attention, with no social media discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0CPE matchmatch criteria | cpe:2.3:a:easy-script_project:easy-script:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.