Ncipher provides hardware security modules and cryptographic key-management solutions that serve as foundational infrastructure for secure communications and data protection across enterprise and telecommunications deployments. The vendor's vulnerability disclosures cluster around its HSM product lines—including nShield, nCore, nForce, and MSCAPI CSP—and reflect the specialized, closed nature of cryptographic appliances where the attack surface and disclosure patterns differ markedly from general-purpose software. Current severity, exploitation activity, and exposure detail are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ncipher over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0063HIGH The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause a | Feb 17, 2004 | 7.5 | 19 | NO | NO |
CVE-2002-1446MEDIUM The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects | Aug 1, 2002 | 5.0 | 19 | NO | NO |
CVE-2001-0081MEDIUM swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to applicat | Feb 12, 2001 | 5.0 | 19 | NO | NO |
CVE-2002-0941MEDIUM The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user abor | Oct 4, 2002 | 4.6 | 18 | NO | NO |
CVE-2006-1116MEDIUM The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which al | Mar 9, 2006 | 5.0 | 15 | NO | NO |
CVE-2002-0940MEDIUM domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, whic | Oct 4, 2002 | 4.6 | 15 | NO | NO |
Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain seque | Nov 23, 2004 | 2.1 | 14 | NO | NO |
CVE-2003-1417MEDIUM nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key | Dec 31, 2003 | 4.4 | 14 | NO | NO |
CVE-2002-0939MEDIUM The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results | Oct 4, 2002 | 4.6 | 14 | NO | NO |
nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an | Mar 9, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ncipher.
Media articles that mention a CVE ID that affects a product developed by Ncipher — matched by CVE ID, not by vendor name.