← Vulnerability feed

Vulnerability record · CVE-2018-5261 · published 2 February 2018

CVE-2018-5261: Flexense diskboss missing encryption vulnerability

Flexense · Diskboss

An issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryption key used for the encryption of the rest of the session, the server and client disclose sensitive information, such as the authentication credentials, to any man-in-the-middle (MiTM) listener.

8.1 CVSS 3.0 High EPSS 0.46% · top 62.8% CWE-311 · Missing encryption
8.1CVSS 3.0 base score, v2 4.3
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryption key used for the encryption of the rest of the session, the server and client disclose sensitive information, such as the authentication credentials, to any man-in-the-middle (MiTM) listener.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-5261 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-5262Flexense diskboss out-of-bounds write vulnerabilityA stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the contex…EPSS 39%8.7CVE-2020-36882Flexense diskboss unrestricted file upload vulnerabilityFlexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial o…EPSS 0.62%8.6CVE-2020-36881Flexense diskboss memory buffer overflow vulnerabilityFlexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to …EPSS 0.37%8.6CVE-2020-36880Flexense diskboss memory buffer overflow vulnerabilityFlexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that allows an attacker to execute…EPSS 0.24%7.8CVE-2017-7310Flexense disk tools XML import buffer overflow allows code executionA buffer overflow in the Import Command of multiple Flexense products (SyncBreeze, DiskSorter, DiskBoss, DiskPulse, DiskSavvy, DupScout, VX Search) b…EPSS 54%analysed7.5CVE-2017-15665Flexense diskboss vulnerabilityIn Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GE…EPSS 9.1%6.1CVE-2018-10294Flexense diskboss cross-site scripting vulnerabilityFlexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS.EPSS 0.69%7.5CVE-2026-34486Apache Tomcat EncryptInterceptor bypass exposes sensitive dataApache Tomcat contains a missing encryption of sensitive data flaw: the fix for CVE-2026-29146 can be bypassed, allowing the EncryptInterceptor to be…KEVEPSS 6.6%analysed

Source: NIST National Vulnerability Database (record CVE-2018-5261), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.