Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxmh-cjjc-hchp

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.

The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.

EPSS

Процентиль: 69%
0.00627
Низкий

Связанные уязвимости

nvd
около 23 лет назад

The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.

EPSS

Процентиль: 69%
0.00627
Низкий