CVE-2024-45165
Last modified
CVE-2024-45165 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key is derived from the string "(c)2007 UCI Software GmbH B.Boll" (without quotes). The key is both static and hardcoded. With access to messages, this results in message decryption and encryption by an attacker. Thus, it enables passive and active man-in-the-middle attacks.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Uci | Idol2 | <= 2.12 |
References
- https://uci.de/download/idol2-client.htmlProduct, Release Notes
- https://www.syss.de/en/responsible-disclosure-policyIssue Tracking
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-45165?
How severe is CVE-2024-45165?
How do I fix CVE-2024-45165?
Are you affected by CVE-2024-45165?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
