{"id":"CVE-2016-6485","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-6485","summary":"Unauthenticated crypto and weak IV in Magento\\Framework\\Encryption","details":"The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.","published":"2019-11-20T01:33:05Z","modified":"2025-02-10T20:19:38.465331Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"magento/community-edition","fixedVersion":"2.2.6"},{"ecosystem":"Packagist","name":"magento/project-community-edition","fixedVersion":null}],"fix":{"url":"https://github.com/magento/magento2/pull/15017","label":"magento/magento2#15017"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-6485"},{"type":"WEB","url":"https://github.com/magento/magento2/pull/15017"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2016-6485.yaml"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/07/19/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/07/27/14"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-10T20:19:38.465331Z"}}