282 – Insecure encryption algorithm - ECB
Description
Encryption algorithms are handled in ECB mode, which is insecure.
Impact
Reverse ciphertext to find sensitive information.
Recommendation
Use algorithms considered cryptographically secure.
Threat
Authorized attacker from the internal network.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: A
- Attack complexity: H
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): L
- Integrity (VI): N
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: P