CVE Vulnerabilities

CVE-2021-33589

Insufficiently Protected Credentials

Published: Apr 21, 2023 | Modified: May 03, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algorithm.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Rnp Ribose * 0.15.1 (excluding)
Rnp Ubuntu kinetic *
Rnp Ubuntu lunar *
Rnp Ubuntu mantic *
Rnp Ubuntu trusty *
Rnp Ubuntu xenial *

Potential Mitigations

References