CVE-2020-7069 is a medium-severity vulnerability affecting PHP versions 7.2.x, 7.3.x, and 7.4.x, specifically when using the openssl_encrypt() function with AES-CCM mode and a 12-byte IV. The flaw causes only the first 7 bytes of the IV to be utilized, leading to decreased security and potentially incorrect encryption. This vulnerability impacts various distributions and products including Canonical, Debian, Fedora, NetApp, openSUSE, Oracle, and Tenable. The vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity and no user interaction, potentially leading to partial confidentiality and integrity compromise. The EPSS score is low, suggesting a low probability of exploitation. Currently, there is no evidence of active exploitation, nor are there any public exploit modules available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with the typical low attention for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.2.0, < 7.2.34CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 7.3.0, < 7.3.23CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 7.4.0, < 7.4.11CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.