Vulnerability Report

CVE-2023-26154

Title: Pubnub C-Core Cryptographic Failures

Cryptographic Failures

Proof Of Concept

No public PoC currently indexed for CVE-2023-26154.

CWE Category CWE-331
Published Date Dec 06, 2023
Modified Date Nov 21, 2024
Exploit Status Not Found
Score 5.9 CVSS v3.1
Exploit Probability (EPSS)
0.95%

Vulnerability Summary

CVE-2023-26154: Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the package github.com/pubnub/go; versions of the package github.com/pubnub/go/v7 before 7.2.0; versions of the package pubnub before 7.3.0; versions of the package pubnub/pubnub before 6.1.0; versions of the package pubnub before 5.3.0; versions of the package pubnub before 0.4.0; versions of the package pubnub/c-core before 4.5.0; versions of the package com.pubnub:pubnub-kotlin before 7.7.0; versions of the package pubnub/swift before 6.2.0; versions of the package pubnub before 5.2.0; versions of the package pubnub before 4.3.0 are vulnerable to Insufficient Entropy via the getKey function, due to inefficient implementation of the AES-256-CBC cryptographic algorithm. The provided encrypt function is less secure when hex encoding and trimming are applied, leaving half of the bits in the key always the same for every encoded message or file. **Note:** In order to exploit this vulnerability, the attacker needs to invest resources in preparing the attack and brute-force the encryption.

Impacted Vendors

Reference Links

https://gist.github.com/vargad/20237094fce7a0a28f0723d7ce395bb0 https://github.com/pubnub/javascript/blob/master/src/crypto/modules/web.js%23L70 https://github.com/pubnub/javascript/commit/fb6cd0417cbb4ba87ea2d5d86a9c94774447e119 https://security.snyk.io/vuln/SNYK-COCOAPODS-PUBNUB-6098384 https://security.snyk.io/vuln/SNYK-DOTNET-PUBNUB-6098372 https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPUBNUBGO-6098373 https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPUBNUBGOV7-6098374 https://security.snyk.io/vuln/SNYK-JAVA-COMPUBNUB-6098371 https://security.snyk.io/vuln/SNYK-JAVA-COMPUBNUB-6098380 https://security.snyk.io/vuln/SNYK-JS-PUBNUB-5840690 https://security.snyk.io/vuln/SNYK-PHP-PUBNUBPUBNUB-6098376 https://security.snyk.io/vuln/SNYK-PUB-PUBNUB-6098385 https://security.snyk.io/vuln/SNYK-PYTHON-PUBNUB-6098375 https://security.snyk.io/vuln/SNYK-RUBY-PUBNUB-6098377 https://security.snyk.io/vuln/SNYK-RUST-PUBNUB-6098378 https://security.snyk.io/vuln/SNYK-SWIFT-PUBNUBSWIFT-6098381 https://security.snyk.io/vuln/SNYK-UNMANAGED-PUBNUBCCORE-6098379 https://gist.github.com/vargad/20237094fce7a0a28f0723d7ce395bb0 https://github.com/pubnub/javascript/blob/master/src/crypto/modules/web.js%23L70 https://github.com/pubnub/javascript/commit/fb6cd0417cbb4ba87ea2d5d86a9c94774447e119 https://security.snyk.io/vuln/SNYK-COCOAPODS-PUBNUB-6098384 https://security.snyk.io/vuln/SNYK-DOTNET-PUBNUB-6098372 https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPUBNUBGO-6098373 https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPUBNUBGOV7-6098374 https://security.snyk.io/vuln/SNYK-JAVA-COMPUBNUB-6098371 https://security.snyk.io/vuln/SNYK-JAVA-COMPUBNUB-6098380 https://security.snyk.io/vuln/SNYK-JS-PUBNUB-5840690 https://security.snyk.io/vuln/SNYK-PHP-PUBNUBPUBNUB-6098376 https://security.snyk.io/vuln/SNYK-PUB-PUBNUB-6098385 https://security.snyk.io/vuln/SNYK-PYTHON-PUBNUB-6098375 https://security.snyk.io/vuln/SNYK-RUBY-PUBNUB-6098377 https://security.snyk.io/vuln/SNYK-RUST-PUBNUB-6098378 https://security.snyk.io/vuln/SNYK-SWIFT-PUBNUBSWIFT-6098381 https://security.snyk.io/vuln/SNYK-UNMANAGED-PUBNUBCCORE-6098379
CVSS v3.1
Source Entity [email protected]
Severity MEDIUM
5.9
Attack Vector
NETWORK
Complexity
HIGH
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
Source Entity [email protected]
Severity MEDIUM
5.9
Attack Vector
NETWORK
Complexity
HIGH
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2023-26154 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity HIGH
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Stack

No specific products linked.