CVE-2016-6485: Magento MAGENTO2
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.
Affected products
- Magento MAGENTO2: affected versions not specified
Published 2017-03-01. Last modified 2026-06-17.