PT-2017-6535 · Thales · Thales Nshield Connect
Published
2017-08-18
·
Updated
2017-09-07
·
CVE-2015-1878
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ versions prior to 11.72
Description
The issue allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key and impersonate the device on a network, affect the integrity and confidentiality of newly created keys, and potentially cause other unspecified impacts using previously loaded keys by connecting to the USB port on the front panel.
Recommendations
For Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ versions prior to 11.72, update to version 11.72 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thales Nshield Connect