CVE-2016-6485: Magento MAGENTO2

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.

Affected products

  • Magento MAGENTO2: affected versions not specified

Published 2017-03-01. Last modified 2026-06-17.