Vulnerability record · CVE-2018-18326 · published 3 July 2019
CVE-2018-18326: DNN (DotNetNuke) weak encryption key entropy from incorrect value conversion
DDnnsoftware · Dotnetnuke
DNN (DotNetNuke) versions 9.2 through 9.2.2 incorrectly converts encryption key source values, producing keys with lower than expected entropy. This is an incomplete fix for CVE-2018-15812, so the underlying weakness in key generation persists. Weak keys undermine the confidentiality protections that depend on them.
Description
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityHigh CVSS (7.5) with no authentication or interaction required, a high EPSS percentile, and an incomplete prior fix make this a serious confidentiality risk despite no KEV listing.
What it is
DNN (DotNetNuke) versions 9.2 through 9.2.2 incorrectly converts encryption key source values, producing keys with lower than expected entropy. This is an incomplete fix for CVE-2018-15812, so the underlying weakness in key generation persists. Weak keys undermine the confidentiality protections that depend on them.
Impact
An attacker who can obtain or observe protected data may be able to recover or brute-force the weakly derived encryption key material, leading to disclosure of confidential information. The CVSS vector indicates high confidentiality impact with no integrity or availability effect.
Attack surface
The flaw is reachable over the network with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). It concerns the platform's internal encryption key derivation rather than a specific exposed endpoint, so any feature relying on those keys is in scope.
Exploitation
CISA KEV does not list this CVE, but EPSS is high (0.54546, ~99th percentile), indicating elevated likelihood of exploitation activity. A reference is tagged Exploit and points to a DotNetNuke cookie deserialization remote code execution write-up, though the record does not state that this specific CVE is the vector used.
What to do
- Upgrade DNN to a release after 9.2.2 that fully addresses CVE-2018-15812 and this incomplete fix.
- Rotate any encryption keys or secrets generated by affected 9.2 through 9.2.2 instances, since existing keys may have low entropy.
- Verify the vendor security center and release notes for the exact fixed version before upgrading.
- Restrict network exposure of DNN instances until patched, since the vector requires no authentication.
Detection
- Audit DNN instances for versions 9.2 through 9.2.2 and confirm patch level.
- Review logs for anomalous access to encrypted data or authentication artifacts that could indicate key recovery attempts.
- Monitor for exploitation attempts tied to DNN cookie handling, given the referenced deserialization exploit write-up.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/dnnsoftware/Dnn.Platform/releases | Release Notes |
| https://www.dnnsoftware.com/community/security/security-center | Vendor Advisory |
| http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/dnnsoftware/Dnn.Platform/releases | Release Notes |
| https://www.dnnsoftware.com/community/security/security-center | Vendor Advisory |
Track CVE-2018-18326 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-18326), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.