LOW · 2.6

CVE-2006-1117

nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other pr...

Vulnerability Description

nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.

CVSS Score

2.6

LOW

AV:N/AC:H/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NcipherDse200 Document Sealing EngineAll versions
NcipherNcoreAll versions
NcipherNforceAll versions
NcipherSecuredbAll versions
NcipherTime Source Master ClockAll versions
NcipherNethsm2.0
NcipherNshieldAll versions
NcipherPayshieldAll versions

References

FAQ

What is CVE-2006-1117?

CVE-2006-1117 is a vulnerability with a CVSS score of 2.6 (LOW). nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other pr...

How severe is CVE-2006-1117?

CVE-2006-1117 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-1117?

Check the references section above for vendor advisories and patch information. Affected products include: Ncipher Dse200 Document Sealing Engine, Ncipher Ncore, Ncipher Nforce, Ncipher Securedb, Ncipher Time Source Master Clock.