CVE-2023-3247


Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP

In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication, random value generator was not checked for failure, and was using narrower range of values than it should have. In case of random generator failure, it could lead to a disclosure of 31 bits of uninitialized memory from the client to the server, and it also made easier to a malicious server to guess the client's nonce. 



We have discovered 1,061,221 live websites that are affected by CVE-2023-3247.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 8 before 8.0.29
  • from 8.1 before 8.1.20
  • from 8.2 before 8.2.7
Total Vulnerable Versions507
Vulnerable Domains1,061,221 live websites (8.77% of PHP install base)


Common Weakness Enumeration


CWE-252 Unchecked Return Value


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-3247 and the relative popularity of websites


Details

  • Published - Jul 22, 2023
  • Updated - Jul 22, 2023

Credits

  • Niels Dossche (reporter)
  • Tim Düsterhus (reporter)





Countries

United States242,363 websites



Germany474,694 websites
France100,403 websites
Netherlands24,396 websites
GB21,447 websites
Russia18,754 websites
Canada14,103 websites
Italy12,722 websites
Japan11,161 websites
Spain10,596 websites

TLDs

.com548,857 websites
.de94,650 websites
.org58,602 websites
.fr44,642 websites
.net41,402 websites
.nl21,254 websites
.ru16,349 websites
.co.uk15,617 websites
.info10,855 websites
.it10,838 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-3247 through included software libraries and plugins.



References


Websites affected by CVE-2023-3247

Top websites that are affected by CVE-2023-3247. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
************.com Germany***
***.******.net Germany*,***
****.com China*,***
***.****.com China*,***
***************.org United States*,***
******.org United States*,***
*************.vip United States*,***
********.org United States*,***
***.***************.com Croatia*,***
***************.org United States*,***
See full domain list