CVE-2014-3503
Apache Syncope uses a weak PNRG
EPSS 6.0%
Description
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.
How to fix CVE-2014-3503
To remediate CVE-2014-3503, upgrade the affected package to a fixed version below.
- Maven/org.apache.syncope:syncope—upgrade to 1.1.8 or later
Is CVE-2014-3503 being exploited?
Moderate — EPSS is 6.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 1.1.0, < 1.1.8