CVE-2017-7252General(botan_project / botan)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • botan

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
botan

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-26: 103-26
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Borne Systems@BorneSystems
    General

    CVE-2017-7252 may sound dated, but it highlights how misconfigurations in your systems lead to serious vulnerabilities. Let's dive into what this means for your enumeration mindset. #OSCP

    Post summary

    The tweet only acknowledges the CVE and suggests misconfigurations can cause serious vulnerabilities, without providing technical or actionable details.

    1000033
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbotan_projectbotan---

Explore more