Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SecureW2 Insecure Pre-Master Secret Generation Vulnerability

SecureW2 is susceptible to an insecure pre-master secret generation vulnerability. This issue is due to a design flaw in the application that causes weak random numbers to be used in a cryptographic operation.

Due to the insecure use of random number generator functions, the secret used in further client-server communications may be predicted by attackers. This may lead to the loss of security properties associated with the EAP-TTLS protocol, leading to a false sense of security.

By exploiting this vulnerability, attackers may gain access to the cleartext contents of encrypted communication, aiding them in further attacks. Man-in-the-middle, and other attacks may also be possible.







 

Privacy Statement
Copyright 2009, SecurityFocus