Skip to content
COOEY

EXPOSURES › CVE-2018-18325

CVE-2018-18325

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-18325 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

DotNetNuke used weak encryption to protect input parameters, an incomplete patch for CVE-2018-15811 that was actively exploited in the wild.

DotNetNuke (DNN) contained an inadequate encryption strength vulnerability due to the use of a weak encryption algorithm to protect input parameters. This CVE resolves an incomplete patch for CVE-2018-15811 and was actively exploited in the wild. DIB orgs should care because weak encryption can lead to data breaches and compliance failures, and the incomplete patch shows negligence in addressing known vulnerabilities.

Shame score — The vendor used weak encryption and failed to properly patch a known vulnerability, leading to active exploitation in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.