PT-2017-6535 · Thales · Thales Nshield Connect
Publicado
2017-08-18
·
Atualizado
2017-09-07
·
CVE-2015-1878
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ versions prior to 11.72
Description
The issue allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key and impersonate the device on a network, affect the integrity and confidentiality of newly created keys, and potentially cause other unspecified impacts using previously loaded keys by connecting to the USB port on the front panel.
Recommendations
For Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ versions prior to 11.72, update to version 11.72 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Thales Nshield Connect