PT-2024-24606 · Tillitis · Tillitis Tkey Signer Device Application

Volokitinss

·

Published

2024-04-23

·

Updated

2024-04-24

·

CVE-2024-32482

CVSS v3.1

2.2

Low

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tillitis TKey signer device application versions prior to 1.0.0
Description A vulnerability has been found in the Tillitis TKey signer device application, an ed25519 signing tool, which makes it possible to disclose portions of the TKey’s data in RAM over the USB interface. To exploit the vulnerability, an attacker needs to use a custom client application and touch the TKey. No secret is disclosed.
Recommendations For versions prior to 1.0.0, upgrade to version 1.0.0 to receive a fix. At the moment, there is no information about other workarounds for this issue.

Exploit

Fix

Out of bounds Read

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2024-32482
GHSA-FRQC-62HV-379P

Affected Products

Tillitis Tkey Signer Device Application