Vulnerability record · CVE-2018-15812 · published 3 July 2019
CVE-2018-15812: DNN weak encryption key entropy in versions 9.2 to 9.2.1
DDnnsoftware · Dotnetnuke
DNN (DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, producing keys with lower than expected entropy. Weak keys undermine the confidentiality guarantees of anything encrypted with them, and the flaw is remotely reachable without authentication. The record does not specify which cryptographic operations or data are affected.
Description
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityNetwork-reachable, unauthenticated weakness in a widely deployed CMS with high EPSS, though the record does not confirm active exploitation or the exact affected cryptographic path.
What it is
DNN (DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, producing keys with lower than expected entropy. Weak keys undermine the confidentiality guarantees of anything encrypted with them, and the flaw is remotely reachable without authentication. The record does not specify which cryptographic operations or data are affected.
Impact
An attacker who can obtain encrypted data or observe cryptographic material may be able to recover plaintext or forge protected values because the key space is smaller than intended. The record does not state whether this leads directly to code execution or data tampering.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the weakness is exposed to unauthenticated remote parties. The description does not identify the specific endpoint or parameter involved.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.475 (98.8th percentile), indicating elevated likelihood of exploitation activity. A referenced Packet Storm item is tagged Exploit and concerns DNN cookie deserialization remote code execution, but the record does not establish that it targets this entropy flaw.
What to do
- Upgrade DNN to a release after 9.2.1; check the vendor security center and GitHub release notes for the fixed version.
- Rotate any encryption keys or secrets generated or stored by affected DNN instances, since low-entropy keys may already be recoverable.
- Restrict network access to DNN administrative and application endpoints to trusted sources until patched.
- Review DNN configuration for custom encryption key sources and replace them with high-entropy values.
- Monitor vendor advisories for follow-up guidance on affected cryptographic components.
Detection
- Inventory DNN instances and confirm version is not 9.2 through 9.2.1.
- Search application and web server logs for anomalous requests to DNN endpoints from unauthenticated clients.
- Alert on unexpected changes to DNN encryption key configuration or key material.
- Correlate DNN host activity with known exploit traffic patterns such as suspicious cookie payloads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/dnnsoftware/Dnn.Platform/releases | Release Notes |
| https://www.dnnsoftware.com/community/security/security-center | Vendor Advisory |
| http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/dnnsoftware/Dnn.Platform/releases | Release Notes |
| https://www.dnnsoftware.com/community/security/security-center | Vendor Advisory |
Track CVE-2018-15812 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-15812), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.