« Volver al listado

CVE-2013-6394

Estado: ModificadaBaja (2.1)—

Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-6394",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-12-13T18:07:54.203",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-12/msg00052.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-02/msg00044.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/11/26/11",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.percona.com/doc/percona-xtrabackup/2.1/release-notes/2.1/2.1.6.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-12/msg00052.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-02/msg00044.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/11/26/11",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.percona.com/doc/percona-xtrabackup/2.1/release-notes/2.1/2.1.6.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks."
    },
    {
      "lang": "es",
      "value": "Percona XtraBackup anterior a 2.1.6 utiliza una cadena constante para el vector de inicialización (IV), que hace que sea más fácil para los usuarios locales vencer los mecanismos de protección de cifrado y llevar a cabo ataques de texto plano."
    }
  ],
  "lastModified": "2026-06-17T00:00:24.603",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:percona:xtrabackup:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40DCDD2E-B90D-4A6B-9BBB-CA8F616DE10C",
              "versionEndIncluding": "2.1.5"
            },
            {
              "criteria": "cpe:2.3:a:percona:xtrabackup:2.1.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D54C790B-111E-494E-9126-941F379AB9D9"
            },
            {
              "criteria": "cpe:2.3:a:percona:xtrabackup:2.1.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6657835F-CA0D-4552-A934-D30A7FCEBD8C"
            },
            {
              "criteria": "cpe:2.3:a:percona:xtrabackup:2.1.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1166693B-05D9-41AD-940E-1E7CF426B757"
            },
            {
              "criteria": "cpe:2.3:a:percona:xtrabackup:2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5109348C-E4E0-4092-A26B-5994CB8449CA"
            },
            {
              "criteria": "cpe:2.3:a:percona:xtrabackup:2.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BD49176-42AA-40A1-BC58-0AA30691626B"
            },
            {
              "criteria": "cpe:2.3:a:percona:xtrabackup:2.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C789D249-BE33-4E39-B48B-91B398056D2D"
            },
            {
              "criteria": "cpe:2.3:a:percona:xtrabackup:2.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CB123BA-D258-419F-81F8-D58A970F9717"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A10BC294-9196-425F-9FB0-B1625465B47F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}