Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ncipher

First CVE: Feb 12, 2001Active for: 25 yearsTotal CVEs: 11
5.8
VTI Score
Low

Ncipher provides hardware security modules and cryptographic key-management solutions that serve as foundational infrastructure for secure communications and data protection across enterprise and telecommunications deployments. The vendor's vulnerability disclosures cluster around its HSM product lines—including nShield, nCore, nForce, and MSCAPI CSP—and reflect the specialized, closed nature of cryptographic appliances where the attack surface and disclosure patterns differ markedly from general-purpose software. Current severity, exploitation activity, and exposure detail are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
4.4
Avg CVSS Score
Higher Avg CVSS Score than 6% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ncipher over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2001
25 years ago
Most Recent CVE
Mar 9, 2006
7,443 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0063HIGH
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause a
Feb 17, 20047.519NONO
CVE-2002-1446MEDIUM
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects
Aug 1, 20025.019NONO
CVE-2001-0081MEDIUM
swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to applicat
Feb 12, 20015.019NONO
CVE-2002-0941MEDIUM
The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user abor
Oct 4, 20024.618NONO
CVE-2006-1116MEDIUM
The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which al
Mar 9, 20065.015NONO
CVE-2002-0940MEDIUM
domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, whic
Oct 4, 20024.615NONO
CVE-2004-0320LOW
Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain seque
Nov 23, 20042.114NONO
CVE-2003-1417MEDIUM
nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key
Dec 31, 20034.414NONO
CVE-2002-0939MEDIUM
The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results
Oct 4, 20024.614NONO
CVE-2006-1115LOW
nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an
Mar 9, 20062.612NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
27%
64%
9%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown11 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown11 (100.0%)
User Interaction
None0 (0.0%)
Unknown11 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown11 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ncipher.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ncipher — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ncipher's Products

View all 1 CNAs →