Vulnerabilities > CVE-2006-2711 - Information Disclosure vulnerability in Secure Elements Class 5 Enterprise vulnerability Management 2.8.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
secure-elements

Summary

Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages. Upgrade to 2.8.1

Vulnerable Configurations

Part Description Count
Application
Secure_Elements
1