Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
CVE-2023-51842
Summary
An algorithm-downgrade issue was discovered in the package meshcentral versions through 1.1.16.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-757 - Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
References
Advisory Timeline
- Published