13 vulnerabilities classified as CWE-320 (密钥管理错误). AI Chinese analysis included.
This page aggregates vulnerability data specifically related to the Key Exposure after Initial TLS Connection weakness, classified under CWE-320. It collects security issues affecting various vendors and products where cryptographic keys remain accessible or improperly managed following the establishment of Transport Layer Security connections. The database covers historical records from the early 2000s through the present, capturing a wide spectrum of implementations across different industries. By centralizing these entries, the platform allows security professionals to track a specific vendor's advisories as they release patches for this distinct class of flaws. Researchers can utilize this resource to understand the broader patterns and recurring mistakes associated with CWE-320, facilitating better risk assessment and mitigation strategies. Additionally, users can look up a particular product's vulnerability history to see past instances of key exposure and evaluate the effectiveness of past remediation efforts. The collection includes details on affected software versions, disclosure dates, and potential impact scopes, providing a comprehensive view of how this weakness manifests in real-world environments. This structured approach helps organizations identify gaps in their cryptographic key management practices and prioritize fixes for exposures that could lead to data interception or unauthorized access. The content is strictly technical, focusing on factual reporting of known issues without speculative commentary.
Vulnerabilities classified as CWE-320 (密钥管理错误) represent 13 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.