cvedb.io
CVE-2017-5999
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2017-03-06T06:59:00.287 · Last modified 2026-06-17T01:21:35.900

Summary

An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core/Crypt.class is using the MCRYPT_RIJNDAEL_256() function (the 256-bit block version of Rijndael, not AES) instead of MCRYPT_RIJNDAEL_128 (real AES) could help an attacker to create unknown havoc in the remote system.

Affected products

syspass — syspass

Does this affect you?

Add your gear to cvedb and we'll alert you only when syspass ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.