← Vulnerability feed

Vulnerability record · CVE-2018-15812 · published 3 July 2019

CVE-2018-15812: DNN weak encryption key entropy in versions 9.2 to 9.2.1

DDnnsoftware · Dotnetnuke

DNN (DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, producing keys with lower than expected entropy. Weak keys undermine the confidentiality guarantees of anything encrypted with them, and the flaw is remotely reachable without authentication. The record does not specify which cryptographic operations or data are affected.

7.5 CVSS 3.1 High EPSS 47% · top 1.2% CWE-331 · CWE-331
7.5CVSS 3.1 base score, v2 5.0
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated weakness in a widely deployed CMS with high EPSS, though the record does not confirm active exploitation or the exact affected cryptographic path.

What it is

DNN (DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, producing keys with lower than expected entropy. Weak keys undermine the confidentiality guarantees of anything encrypted with them, and the flaw is remotely reachable without authentication. The record does not specify which cryptographic operations or data are affected.

Impact

An attacker who can obtain encrypted data or observe cryptographic material may be able to recover plaintext or forge protected values because the key space is smaller than intended. The record does not state whether this leads directly to code execution or data tampering.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the weakness is exposed to unauthenticated remote parties. The description does not identify the specific endpoint or parameter involved.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.475 (98.8th percentile), indicating elevated likelihood of exploitation activity. A referenced Packet Storm item is tagged Exploit and concerns DNN cookie deserialization remote code execution, but the record does not establish that it targets this entropy flaw.

What to do

  • Upgrade DNN to a release after 9.2.1; check the vendor security center and GitHub release notes for the fixed version.
  • Rotate any encryption keys or secrets generated or stored by affected DNN instances, since low-entropy keys may already be recoverable.
  • Restrict network access to DNN administrative and application endpoints to trusted sources until patched.
  • Review DNN configuration for custom encryption key sources and replace them with high-entropy values.
  • Monitor vendor advisories for follow-up guidance on affected cryptographic components.

Detection

  • Inventory DNN instances and confirm version is not 9.2 through 9.2.1.
  • Search application and web server logs for anomalous requests to DNN endpoints from unauthenticated clients.
  • Alert on unexpected changes to DNN encryption key configuration or key material.
  • Correlate DNN host activity with known exploit traffic patterns such as suspicious cookie payloads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15812 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-9822DNN (DotNetNuke) cookie deserialization remote code executionDNN (DotNetNuke) before 9.1.1 deserializes attacker-controlled cookie data, allowing remote code execution. The flaw is a code injection (CWE-94) rea…KEVEPSS 95%analysed7.5CVE-2018-15811DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.1 use a weak encryption algorithm to protect input parameters. Because the protection is inadequate, data t…KEVEPSS 76%analysed7.5CVE-2018-18325DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters, and the issue persists because the fix for C…KEVEPSS 74%analysed10.0CVE-2006-3601Dnnsoftware dotnetnuke vulnerability** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileg…EPSS 2.5%9.8CVE-2025-64095Dnnsoftware dotnetnuke unrestricted file upload vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML edito…EPSS 45%9.8CVE-2015-2794DotNetNuke install wizard allows unauthenticated reinstall and SuperUser takeoverThe installation wizard in DotNetNuke (DNN) before 7.4.1 can be reached directly at Install/InstallWizard.aspx and used to reinstall the application.…EPSS 75%analysed9.0CVE-2025-59545Dnnsoftware dotnetnuke cross-site scripting vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt mod…EPSS 0.49%8.8CVE-2025-52487Dnnsoftware dotnetnuke incorrect authorization vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2018-15812), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.