AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-7822

MEDIUM · CVSS 5.3 EPSS 1.42%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-06-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-7822
Severity
MEDIUM
CVSS
5.3
EPSS
1.42%
Firefox

Original NVD Description

The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NIST Special Publication 800-38D specification. This might allow for the authentication key to be determined in some instances. This vulnerability affects Firefox < 56.