Vulnerability record · CVE-2020-8173 · published 2 November 2020
CVE-2020-8173: Nextcloud server missing encryption vulnerability
Nextcloud · Nextcloud Server
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
Description
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://hackerone.com/reports/852841 | ExploitThird Party Advisory |
| https://nextcloud.com/security/advisory/?id=NC-SA-2020-023 | Broken LinkVendor Advisory |
| https://hackerone.com/reports/852841 | ExploitThird Party Advisory |
| https://nextcloud.com/security/advisory/?id=NC-SA-2020-023 | Broken LinkVendor Advisory |
Track CVE-2020-8173 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8173), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.