Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2197

Опубликовано: 01 мая 2023
Источник: nvd
CVSS3: 2.5
CVSS3: 2.5
EPSS Низкий

Описание

HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key. Fixed in 1.13.2

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
Версия от 1.13.0 (включая) до 1.13.2 (исключая)

EPSS

Процентиль: 5%
0.00023
Низкий

2.5 Low

CVSS3

2.5 Low

CVSS3

Дефекты

CWE-326
CWE-326
CWE-326

Связанные уязвимости

CVSS3: 2.5
redhat
почти 3 года назад

HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key. Fixed in 1.13.2

CVSS3: 2.5
github
больше 2 лет назад

HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key. Fixed in 1.13.2

EPSS

Процентиль: 5%
0.00023
Низкий

2.5 Low

CVSS3

2.5 Low

CVSS3

Дефекты

CWE-326
CWE-326
CWE-326