Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

nCipher Testing Options Insecure Key Generation Vulnerabilities


Certain nCipher products are susceptible to insecure key-generation vulnerabilities. These issues are due to the unintended inclusion of testing functionality in the affected software.

These issues may result in the creation of cryptographic keys that may have properties that allow attackers to recover the private key in significantly less time than with brute-force attacks.

By gaining access to private keys, attackers may gain access to potentially sensitive information, perform man-in-the-middle attacks, or bypass security restrictions that depend on the security properties of the affected keys. Other attacks may also be possible.







 

Privacy Statement
Copyright 2009, SecurityFocus