CVE Vulnerabilities

CVE-2021-33589

Insufficiently Protected Credentials

Published: Apr 21, 2023 | Modified: Feb 04, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algorithm.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
RnpRibose*0.15.1 (excluding)
RnpUbuntukinetic*
RnpUbuntulunar*
RnpUbuntumantic*
RnpUbuntuoracular*
RnpUbuntuplucky*
RnpUbuntutrusty*
RnpUbuntuxenial*

Potential Mitigations

References