云虫漏洞情报

CVE-2026-81681 - openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace directory is actually stored in cleartext and the derived encryption key is never applied to it. A user who trusts the branding and places files in the workspace leaves them unencrypted on the removable media, so an attacker with physical access to the - 漏洞详情

漏洞编号:CVE-2026-81681

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-81681

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-311

发布/更新时间:2026-08-27 / 2026-08-28

漏洞描述

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace directory is actually stored in cleartext and the derived encryption key is never applied to it. A user who trusts the branding and places files in the workspace leaves them unencrypted on the removable media, so an attacker with physical access to the media can read the sensitive files. Fixed in 1.4.9, which seals the workspace into an authenticated AES-256-GCM vault.

相关链接

相关漏洞

« 返回首页