Deprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIME
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 2.3epss 0.2%
probabilidad de explotación
0.2%top 92% de las CVE
explotación observada
noninguna fuente lo reporta
Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
Best Practical Solutions · Request TrackerReferencias
https://docs.bestpractical.com/release-notes/rt/4.4.8https://docs.bestpractical.com/release-notes/rt/5.0.8https://lists.debian.org/debian-lts-announce/2025/05/msg00009.htmlhttps://www.incibe.es/en/incibe-cert/notices/aviso/cryptographic-algorithm-not-recommended-request-tracker-best-practical