CVE-2017-12871 describes a medium-severity vulnerability in SimpleSAMLphp versions 1.14.x through 1.14.11, specifically within the aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php. This flaw allows remote attackers to bypass encryption by exploiting the use of the first 16 bytes of the secret key as the initialization vector (IV). The vulnerability has a CVSS score of 5.9, indicating a high impact on confidentiality with high attack complexity and no user interaction required. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14.0CPE matchmatch criteria | cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.0:*:*:*:*:*:*:* | ||
1.14.1CPE matchmatch criteria | cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.1:*:*:*:*:*:*:* | ||
1.14.2CPE matchmatch criteria | cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.2:*:*:*:*:*:*:* | ||
1.14.3CPE matchmatch criteria | cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.3:*:*:*:*:*:*:* | ||
1.14.4CPE matchmatch criteria | cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.