In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.
We have discovered 359,469 live websites that are affected by CVE-2020-7069.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 359,469 live websites (4.89% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 68 versions ( 13% of all versions) |
| 121,394 websites | |
| 126,923 websites | |
| 11,361 websites | |
| 11,112 websites | |
| 10,565 websites | |
| 6,838 websites | |
| 5,959 websites | |
| 5,861 websites | |
| 5,046 websites | |
| 4,492 websites |
| .com | 129,662 websites |
| .ru | 68,262 websites |
| .fr | 51,950 websites |
| .org | 12,071 websites |
| .net | 10,293 websites |
| .be | 6,469 websites |
| .de | 5,997 websites |
| .pl | 5,564 websites |
| .it | 4,923 websites |
| .nl | 3,283 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *.cn | *,*** | ||
| *****.pl | *,*** | ||
| ****.neustar | *,*** | ||
| *********.com | *,*** | ||
| ****.com | *,*** | ||
| *****.com | *,*** | ||
| ******.com | *,*** | ||
| **********.com | *,*** | ||
| ***.****.gov | *,*** | ||
| *****.**.com | *,*** |
FAQ