ValiCert Enterprise Validation Authority (EVA)...
High severity
Unreviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Feb 15, 2024
Description
Published by the National Vulnerability Database
Dec 4, 2001
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Feb 15, 2024
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.
References