PT-2022-28091 · Tss-Lib · Tss-Lib

Published

2022-12-22

·

Updated

2023-08-08

·

CVE-2022-47931

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions tss-lib versions prior to 2.0.0
Description The issue concerns a collision of hash values. This collision can potentially lead to security issues, although specific details about exploitation or affected devices are not provided.
Recommendations For versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue. As a temporary workaround, consider implementing additional hash value validation to minimize the risk of collision exploitation.

Fix

Use of a Broken Cryptographic Algorithm

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2022-47931
GHSA-CVCX-G7WH-X8RF
GO-2023-1904

Affected Products

Tss-Lib