Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

nCipher Insecure CBC-MAC API Vulnerability

Certain nCipher products are susceptible to an insecure CBC-MAC (Cipher Block Chaining-Message Authentication Code) API vulnerability. This issue is due to a flaw in the API that allows programmers to use insecure CBC-MAC IVs (Initialization Vector).

This issue allows remote attackers to modify data that is protected by the affected CBC-MAC protocol. This allows attackers to perform man-in-the-middle attacks against software that uses the affected insecure APIs. Other attacks may also be possible.







 

Privacy Statement
Copyright 2009, SecurityFocus