PT-2023-18262 · Samsung · Samsung Blockchain Keystore

Published

2023-05-04

·

Updated

2023-05-10

·

CVE-2023-21507

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Blockchain Keystore versions prior to 1.3.12.1
Description The issue is related to an Out-of-bounds Read while processing the BC TUI CMD SEND RESOURCE DATA ARRAY command in the bc tui trustlet. This allows a local attacker to read arbitrary memory.
Recommendations For versions prior to 1.3.12.1, update to version 1.3.12.1 or later to resolve the issue.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2023-21507

Affected Products

Samsung Blockchain Keystore