CVE-2013-7469
HIGHSeafile < 6.2.11 - Inadequate Encryption Strength via Static IV in CBC Mode
Title source: llmDescription
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/haiwen/seafile/issues/350
Third Party Advisory x_refsource_misc
https://drive.google.com/file/d/1rwYsnuhZZxmSR6Zs8rJlWW3R27XBOSJU/view
Scores
CVSS v3
7.5
EPSS
0.0109
EPSS Percentile
60.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-326
Status
published
Products (1)
seafile/seafile
< 6.2.11
Published
Feb 21, 2019
Tracked Since
Feb 18, 2026