Skip to content
COOEY

EXPOSURES › CVE-2018-15811

CVE-2018-15811

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-15811 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

DotNetNuke used weak encryption to protect input parameters, a flaw listed in CISA's KEV catalog.

DotNetNuke (DNN) contained an inadequate encryption strength vulnerability due to the use of a weak encryption algorithm to protect input parameters. This failure matters to DIB organizations because weak encryption can lead to data exposure and compliance violations under NIST 800-171. Organizations should ensure all software components use strong, modern encryption algorithms and regularly patch known vulnerabilities.

Shame score — The vendor shipped software with a known weak encryption algorithm that was later recognized as exploitable and added to CISA's KEV catalog, indicating avoidable negligence in cryptographic design and patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -1.00
negative
"DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.