CVE-2023-51839
JavaScript vulnerability analysis and mitigation

Overview

DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm. The vulnerability (CVE-2023-51839) was discovered in the lib/util/vncauth.js file, line 35, where the software implements the DES-ECB encryption algorithm. The issue was reported on December 8, 2023, and affects the authentication mechanism of the software (GitHub Issue, Advisory).

Technical details

The vulnerability stems from the use of DES-ECB (Data Encryption Standard in Electronic Code Book mode) for encryption. The implementation uses a fixed encryption key and lacks an initialization vector (IV). This cryptographic algorithm is considered broken and risky because it produces identical output for identical input blocks, making it vulnerable to pattern recognition attacks. The CVSS v3.1 base score for this vulnerability is 9.1 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) (NVD).

Impact

The vulnerability can lead to information disclosure and potential escalation of privileges. Due to the predictable nature of DES-ECB encryption, attackers can potentially compromise the confidentiality and integrity of sensitive data by exploiting patterns in the encrypted data (Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23744CRITICAL9.8
  • JavaScriptJavaScript
  • @mcpjam/inspector
NoYesJan 16, 2026
CVE-2026-23735HIGH8.7
  • JavaScriptJavaScript
  • graphql-modules
NoYesJan 16, 2026
GHSA-gw32-9rmw-qwwwHIGH8.4
  • JavaScriptJavaScript
  • svelte
NoYesJan 16, 2026
CVE-2026-23745HIGH8.2
  • JavaScriptJavaScript
  • tar
NoYesJan 16, 2026
GHSA-38cw-85xc-xr9xMEDIUM6.8
  • JavaScriptJavaScript
  • @veramo/data-store
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management