poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
History

Sun, 17 Aug 2025 04:15:00 +0000

Type Values Removed Values Added
Description poco v1.14.1-release was discovered to contain weak encryption. poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.

Thu, 14 Aug 2025 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pocoproject:poco:1.14.1:*:*:*:*:*:*:*

Tue, 12 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Pocoproject
Pocoproject poco
Vendors & Products Pocoproject
Pocoproject poco

Wed, 06 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-327
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
Description poco v1.14.1-release was discovered to contain weak encryption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-06T00:00:00.000Z

Updated: 2025-08-17T03:57:24.360Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-45766

cve-icon Vulnrichment

Updated: 2025-08-06T19:36:33.922Z

cve-icon NVD

Status : Modified

Published: 2025-08-06T20:15:28.953

Modified: 2025-08-17T04:15:33.243

Link: CVE-2025-45766

cve-icon Redhat

No data.