CVE-2017-5999 describes a cryptographic weakness in sysPass 2.x before 2.1, where the application incorrectly uses MCRYPT_RIJNDAEL_256 instead of the more secure MCRYPT_RIJNDAEL_128 (AES) for encryption. This vulnerability, rated HIGH with a CVSS score of 7.5, allows an unauthenticated attacker to remotely compromise the confidentiality of sensitive data due to the use of a cryptographically weak algorithm. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:syspass:syspass:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.