CVE-2013-6078
Description
The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging unspecified "security concerns," aka the ESA-2013-068 issue. NOTE: this issue has been SPLIT from CVE-2007-6755 because the vendor announcement did not state a specific technical rationale for a change in the algorithm; thus, CVE cannot reach a conclusion that a CVE-2007-6755 concern was the reason, or one of the reasons, for this change.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:emc:rsa_bsafe_toolkits:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:emc:rsa_bsafe_toolkits:-:*:*:*:*:*:*:*
- (no CPE)
cpe:2.3:a:emc:rsa_data_protection_manager:20130918:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:emc:rsa_data_protection_manager:20130918:*:*:*:*:*:*:*
- (no CPE)range: = 20130918
Patches
Vulnerability mechanics
References
4- arstechnica.com/security/2013/09/stop-using-nsa-influence-code-in-our-product-rsa-tells-customers/nvd
- blog.cryptographyengineering.com/2013/09/rsa-warns-developers-against-its-own.htmlnvd
- stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2-332655/nvd
- threatpost.com/in-wake-of-latest-crypto-revelations-everything-is-suspectnvd
News mentions
0No linked articles in our index yet.