Pending AI Enrichment

This vulnerability was recently detected via the live feed and has not yet been processed by Precogs AI's context enrichment engine. The data below represents raw telemetric data.

RAW NVD TELEMETRY

CVE-2023-31135

CVSS Base Score
3.3 MEDIUM
Primary Weakness
CWE-326
Published Date
May 17, 2023
Data Source
NVD API

Dgraph is an open source distributed GraphQL database. Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. The first 12 bytes come from a baseIv which is initialized when an audit log is created. The last 4 bytes come from the length of the log line being encrypted. This is problematic because two log lines will often have the same length, so due to these collisions we are reusing the same nonce many times. All audit logs generated by versions of Dgraph <v23.0.0 are affected. Attackers must have access to the system the logs are stored on. Dgraph users should upgrade to v23.0.0. Users unable to upgrade should store existing audit logs in a secure location and for extra security, encrypt using an external tool like `gpg`.

Related Vulnerabilitiesvia CWE-326

CVE-2022-451419.8 CRITICAL

CWE-328 in Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96)

CWE-328CWE-326CWE-326
CVE-2018-183257.5 HIGH

Inadequate Encryption Strength in DNN (aka DotNetNuke) 9

CWE-326CWE-326
CVE-2018-04489.8 CRITICAL

Inadequate Encryption Strength in A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions

CWE-326CWE-326
CVE-2015-05759.8 CRITICAL

Inadequate Encryption Strength in In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure ciphersuites were included in the default configuration

CWE-326
CVE-2014-99759.8 CRITICAL

Inadequate Encryption Strength in In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback vulnerability potentially exists in Full Disk Encryption

CWE-326
CVE-2017-76739.8 CRITICAL

Improper Restriction of Excessive Authentication Attempts in Apache OpenMeetings 1

CWE-307CWE-326

Is your system affected?

Precogs AI detects CVE-2023-31135 in compiled binaries, LLMs, and application layers — even without source code access.