CVE-2023-46133 describes a critical weakness in the CryptoES library, affecting its PBKDF2 implementation prior to version 2.1.0. This vulnerability stems from defaulting to the insecure SHA1 algorithm and a single iteration, significantly weakening the cryptographic strength for password protection and signature generation. Rated 9.1 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), the vulnerability is easily exploitable over the network with low attack complexity, leading to high impact on confidentiality and integrity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, suggesting it has not yet garnered widespread attention from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.0CPE matchmatch criteria | cpe:2.3:a:entronad:cryptoes:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.