CVE-2023-21626

CVSS v3 Score
7.1
High

Vulnerability Description

Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.

CVSS:7.1(High)

Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.

CVSS:6.8(Medium)

A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Softwa...

CVSS:6.8(Medium)

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker ...

CVSS:7.4(High)

Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.

CVSS:7.4(High)

MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic

CVSS:7.5(High)

D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless key.