CVE-2022-26083
Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
- EPSS probability
- 0.06%
- CWE
- CWE-1204
- Published
- 2025-02-14
- Last modified
- 2026-03-13
Affected products
- n/a Intel(R) IPP Cryptography software library
Weakness type
Related vulnerabilities
- CVE-2026-5087 — PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely
- CVE-2026-25998 — strongMan vulnerable to private credential recovery due to key and counter reuse
- CVE-2025-0714 — Insecure storage of sensitive information in MobaXTerm <25.0.
- CVE-2023-2747 — Uninitialized IV in Silicon Labs SE FW v2.0.0 through v 2.2.1 for internally stored data