|
SecureW2 Insecure Pre-Master Secret Generation Vulnerability
SecureW2 is susceptible to an insecure pre-master secret generation vulnerability. This issue is due to a design flaw in the application that causes weak random numbers to be used in a cryptographic operation. Due to the insecure use of random number generator functions, the secret used in further client-server communications may be predicted by attackers. This may lead to the loss of security properties associated with the EAP-TTLS protocol, leading to a false sense of security. By exploiting this vulnerability, attackers may gain access to the cleartext contents of encrypted communication, aiding them in further attacks. Man-in-the-middle, and other attacks may also be possible. |
|
|
Privacy Statement |