{
  "affected": [
    {
      "database_specific": {
        "unresolved_ranges": [
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.0"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "2.x"
              },
              {
                "fixed": "2.1"
              }
            ]
          }
        ]
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "a0e2c485e53b370a7cc6d833e192c3c5bfd70e1f"
            }
          ],
          "repo": "https://github.com/nuxsmin/syspass",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "81cc9e38db2a5f47efc46575db88ccd6dbf29204"
            }
          ],
          "repo": "https://github.com/nuxsmin/syspass",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "a0e2c485e53b370a7cc6d833e192c3c5bfd70e1f"
            }
          ],
          "repo": "https://github.com/nuxsmin/syspass",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "81cc9e38db2a5f47efc46575db88ccd6dbf29204"
            }
          ],
          "repo": "https://github.com/nuxsmin/syspass",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core/Crypt.class is using the MCRYPT_RIJNDAEL_256() function (the 256-bit block version of Rijndael, not AES) instead of MCRYPT_RIJNDAEL_128 (real AES) could help an attacker to create unknown havoc in the remote system.",
  "id": "CVE-2017-5999",
  "modified": "2026-03-15T21:49:07.543695900Z",
  "published": "2017-03-06T06:59:00.287Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://cxsecurity.com/issue/WLB-2017020196"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securityfocus.com/bid/96562"
    },
    {
      "type": "FIX",
      "url": "https://github.com/nuxsmin/sysPass/commit/a0e2c485e53b370a7cc6d833e192c3c5bfd70e1f"
    },
    {
      "type": "FIX",
      "url": "https://github.com/nuxsmin/sysPass/releases/tag/2.1.0.17022601"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}