漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WireGuard Easy Weak Token Generation Information Disclosure via OTL Route
Vulnerability Description
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of at most 1000 candidate tokens per client ID, as the token is computed using CRC32 over a random value constrained to 0-999. Attackers can enumerate candidate tokens against the unauthenticated /cnf/:oneTimeLink route, which lacks rate limiting and does not validate token expiration, to obtain a peer's PrivateKey and PresharedKey and impersonate that peer on the VPN network.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Vulnerability Type
使用具有密码学弱点缺陷的PRNG
Vulnerability Title
WireGuard Easy wg-easy 加密问题漏洞
Vulnerability Description
WireGuard Easy wg-easy是WireGuard Easy组织开源的一款简化WireGuard配置管理的Web界面工具。 WireGuard Easy wg-easy 15.3.0版本及之前版本存在安全漏洞,该漏洞源于一次性链接令牌生成加密强度薄弱,令牌使用CRC32在0-999范围内随机值计算,且/cnf/:oneTimeLink路由缺少速率限制并未验证令牌过期,允许未经身份验证的攻击者通过暴力破解候选令牌恢复WireGuard对等凭据。
CVSS Information
N/A
Vulnerability Type
N/A