PT-2017-11422 · Osci · Osci Transport Library
Marc Nimmerrichter
+1
·
Published
2017-06-30
·
Updated
2017-07-06
·
CVE-2017-10669
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OSCI Transport Library versions 1.6 through 1.6.1
Description
The issue allows an attacker with access to unencrypted OSCI protocol messages to send crafted protocol messages with duplicate IDs, potentially exploiting the Signature Wrapping vulnerability in OSCI-Transport 1.2 as used in the OSCI Transport Library.
Recommendations
For OSCI Transport Library versions 1.6 through 1.6.1, consider implementing encryption for OSCI protocol messages to prevent unauthorized access and mitigate the risk of exploitation. As a temporary workaround, restrict access to unencrypted OSCI protocol messages until a patch is available.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Osci Transport Library