CVE-2020-7069

Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.


We have discovered 359,469 live websites that are affected by CVE-2020-7069.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains359,469 live websites (4.89% of PHP install base)
Vulnerable Versions
  • from 7.2 through 7.2.34
  • from 7.3 through 7.3.23
  • from 7.4 through 7.4.11
Vulnerable Versions Count68 versions ( 13% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Oct 2, 2020
  • Updated - Sep 17, 2024

Credits

  • Reported by bizxing at web dot de

Website Distribution by Country

Number of websites using CVE-2020-7069
United States121,394 websites



France126,923 websites
Germany11,361 websites
Russia11,112 websites
China10,565 websites
Japan6,838 websites
Netherlands5,959 websites
Poland5,861 websites
Italy5,046 websites
GB4,492 websites

Website Distribution by TLD

Number of websites using CVE-2020-7069
.com129,662 websites
.ru68,262 websites
.fr51,950 websites
.org12,071 websites
.net10,293 websites
.be6,469 websites
.de5,997 websites
.pl5,564 websites
.it4,923 websites
.nl3,283 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-7069

Top websites that are affected by CVE-2020-7069. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*.cn China*,***
*****.pl Poland*,***
****.neustar United States*,***
*********.com China*,***
****.com China*,***
*****.com United States*,***
******.com France*,***
**********.com France*,***
***.****.gov United States*,***
*****.**.com China*,***
See full domain list

FAQ

CVE-2020-7069 is Improper Input Validation in PHP
A total of 359,469 websites have been identified as vulnerable to CVE-2020-7069, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2020-7069 vulnerability.
PHP versions up to 7.4.11 are vulnerable to CVE-2020-7069.
CVE-2020-7069 is resolved in version 7.4.11 of PHP.

References