PT-2017-6535 · Thales · Thales Nshield Connect

Published

2017-08-18

·

Updated

2017-09-07

·

CVE-2015-1878

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ versions prior to 11.72
Description The issue allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key and impersonate the device on a network, affect the integrity and confidentiality of newly created keys, and potentially cause other unspecified impacts using previously loaded keys by connecting to the USB port on the front panel.
Recommendations For Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ versions prior to 11.72, update to version 11.72 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1878

Affected Products

Thales Nshield Connect