← Back

Ncipher

ncipher

11 CVEs • 15 products

Products (15)

Click to collapse
Toggle
Mscapi Csp
mscapi_csp
Nshield
nshield
Nforce
nforce
Ncore
ncore
Ncipher
ncipher
Chil
chil
Securedb
securedb
Nethsm
nethsm
Payshield
payshield

CVEs (11)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ncipher
8Dse200 Document Sealing Engine
NcoreNethsm+5 more
Apr 16, 2026
Mar 9, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains cer...Show more
nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.Show less
1Ncipher
1Ncore
Apr 16, 2026
Mar 9, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrit...Show more
The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrity checks and modify messages without being detected.Show less
1Ncipher
3Chil
Mscapi CspNcipher Software Cd
Apr 16, 2026
Mar 9, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an attacker to crack the private key in si...Show more
nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an attacker to crack the private key in significantly less time than a brute force attack.Show less
1Ncipher
1Nshield
Apr 16, 2026
Nov 23, 2004
N/A· v4
N/A· v3
2.1 LOW· v2
Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain sequences of commands.
1Ncipher
1Payshield Spp Library
Apr 16, 2026
Feb 17, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-c...Show more
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.Show less
1Ncipher
1Support Software
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.4 MEDIUM· v2
nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.d...Show more
nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.Show less
1Ncipher
2Nforce
Nshield
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for...Show more
The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges.Show less
1Ncipher
1Mscapi Csp
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
4.6 MEDIUM· v2
domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level th...Show more
domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).Show less
1Ncipher
1Mscapi Csp
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specifi...Show more
The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).Show less
1Ncipher
1Pkcs 11 Library
Apr 16, 2026
Aug 1, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow...Show more
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.Show less
1Ncipher
1Ncipher
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.