← Vulnerability feed

Vulnerability record · CVE-2018-18326 · published 3 July 2019

CVE-2018-18326: DNN (DotNetNuke) weak encryption key entropy from incorrect value conversion

DDnnsoftware · Dotnetnuke

DNN (DotNetNuke) versions 9.2 through 9.2.2 incorrectly converts encryption key source values, producing keys with lower than expected entropy. This is an incomplete fix for CVE-2018-15812, so the underlying weakness in key generation persists. Weak keys undermine the confidentiality protections that depend on them.

7.5 CVSS 3.1 High EPSS 54% · top 1.0% CWE-331 · CWE-331
7.5CVSS 3.1 base score, v2 5.0
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityHigh CVSS (7.5) with no authentication or interaction required, a high EPSS percentile, and an incomplete prior fix make this a serious confidentiality risk despite no KEV listing.

What it is

DNN (DotNetNuke) versions 9.2 through 9.2.2 incorrectly converts encryption key source values, producing keys with lower than expected entropy. This is an incomplete fix for CVE-2018-15812, so the underlying weakness in key generation persists. Weak keys undermine the confidentiality protections that depend on them.

Impact

An attacker who can obtain or observe protected data may be able to recover or brute-force the weakly derived encryption key material, leading to disclosure of confidential information. The CVSS vector indicates high confidentiality impact with no integrity or availability effect.

Attack surface

The flaw is reachable over the network with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). It concerns the platform's internal encryption key derivation rather than a specific exposed endpoint, so any feature relying on those keys is in scope.

Exploitation

CISA KEV does not list this CVE, but EPSS is high (0.54546, ~99th percentile), indicating elevated likelihood of exploitation activity. A reference is tagged Exploit and points to a DotNetNuke cookie deserialization remote code execution write-up, though the record does not state that this specific CVE is the vector used.

What to do

  • Upgrade DNN to a release after 9.2.2 that fully addresses CVE-2018-15812 and this incomplete fix.
  • Rotate any encryption keys or secrets generated by affected 9.2 through 9.2.2 instances, since existing keys may have low entropy.
  • Verify the vendor security center and release notes for the exact fixed version before upgrading.
  • Restrict network exposure of DNN instances until patched, since the vector requires no authentication.

Detection

  • Audit DNN instances for versions 9.2 through 9.2.2 and confirm patch level.
  • Review logs for anomalous access to encrypted data or authentication artifacts that could indicate key recovery attempts.
  • Monitor for exploitation attempts tied to DNN cookie handling, given the referenced deserialization exploit write-up.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-18326 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-9822DNN (DotNetNuke) cookie deserialization remote code executionDNN (DotNetNuke) before 9.1.1 deserializes attacker-controlled cookie data, allowing remote code execution. The flaw is a code injection (CWE-94) rea…KEVEPSS 95%analysed7.5CVE-2018-15811DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.1 use a weak encryption algorithm to protect input parameters. Because the protection is inadequate, data t…KEVEPSS 76%analysed7.5CVE-2018-18325DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters, and the issue persists because the fix for C…KEVEPSS 74%analysed10.0CVE-2006-3601Dnnsoftware dotnetnuke vulnerability** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileg…EPSS 2.5%9.8CVE-2025-64095Dnnsoftware dotnetnuke unrestricted file upload vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML edito…EPSS 45%9.8CVE-2015-2794DotNetNuke install wizard allows unauthenticated reinstall and SuperUser takeoverThe installation wizard in DotNetNuke (DNN) before 7.4.1 can be reached directly at Install/InstallWizard.aspx and used to reinstall the application.…EPSS 75%analysed9.0CVE-2025-59545Dnnsoftware dotnetnuke cross-site scripting vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt mod…EPSS 0.49%8.8CVE-2025-52487Dnnsoftware dotnetnuke incorrect authorization vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2018-18326), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.