Vulnerability CVE-2020-10256


Published: 2020-10-27

Description:
An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption.

Type:

CWE-335

(PRNG Seed Error)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
1password -> Command-line 
1password -> SCIM 

 References:
https://support.1password.com/command-line/
https://support.1password.com/kb/202010/
https://support.1password.com/scim/

Copyright 2024, cxsecurity.com

 

Back to Top