PT-2024-24606 · Tillitis · Tillitis Tkey Signer Device Application
Volokitinss
·
Published
2024-04-23
·
Updated
2024-04-24
·
CVE-2024-32482
CVSS v3.1
2.2
Low
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Tillitis TKey signer device application versions prior to 1.0.0
Description
A vulnerability has been found in the Tillitis TKey signer device application, an ed25519 signing tool, which makes it possible to disclose portions of the TKey’s data in RAM over the USB interface. To exploit the vulnerability, an attacker needs to use a custom client application and touch the TKey. No secret is disclosed.
Recommendations
For versions prior to 1.0.0, upgrade to version 1.0.0 to receive a fix.
At the moment, there is no information about other workarounds for this issue.
Exploit
Fix
Out of bounds Read
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tillitis Tkey Signer Device Application