CVE-2020-7069

Updated: 2025-08-20 00:19:06.745939

Description:

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 6.4
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 php 8.0 6.5 MEDIUM Ignored 2025-05-29 03:54:44
Debian 10 php 5.6 6.5 MEDIUM Ignored 2025-05-29 03:54:44
Debian 10 php 7.3 6.5 MEDIUM Ignored 2025-05-29 03:54:44
Debian 10 php 8.2 6.5 MEDIUM Ignored 2025-05-29 03:54:44
Debian 10 php 8.1 6.5 MEDIUM Ignored 2025-05-29 03:54:44
Debian 10 php 7.0 6.5 MEDIUM Ignored 2025-05-29 03:54:44
Debian 10 php 7.1 6.5 MEDIUM Ignored 2025-05-29 03:54:44
Debian 10 php 7.2 6.5 MEDIUM Ignored 2025-05-29 03:54:44
Debian 10 php 7.4 6.5 MEDIUM Ignored 2025-05-29 03:54:44
Debian 11 php 8.1 6.5 MEDIUM Ignored 2025-05-29 03:54:43
Total: 146