9.8
CVSSv3

CVE-2020-10256

Published: 27/10/2020 Updated: 25/03/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in beta versions of the 1Password command-line tool before 0.5.5 and in beta versions of the 1Password SCIM bridge before 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

1password scim

1password command line interface