EXPOSURES › CVE-2018-15811
CVE-2018-15811
HIGH ⌖ ON CISA KEV · EXPLOITEDDotNetNuke used weak encryption to protect input parameters, a flaw listed in CISA's KEV catalog.
DotNetNuke (DNN) contained an inadequate encryption strength vulnerability due to the use of a weak encryption algorithm to protect input parameters. This failure matters to DIB organizations because weak encryption can lead to data exposure and compliance violations under NIST 800-171. Organizations should ensure all software components use strong, modern encryption algorithms and regularly patch known vulnerabilities.
Shame score — The vendor shipped software with a known weak encryption algorithm that was later recognized as exploitable and added to CISA's KEV catalog, indicating avoidable negligence in cryptographic design and patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
"DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters."