PT-2024-33517 · Unknown · Blockchain Keystore

Sam

·

Published

2024-11-05

·

Updated

2024-11-13

·

CVE-2024-49406

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blockchain Keystore versions prior to 1.3.16
Description The issue is related to improper validation of the integrity check value in the Blockchain Keystore, allowing local attackers with root privileges to modify transactions.
Recommendations For versions prior to 1.3.16, update to version 1.3.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the Blockchain Keystore to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-49406

Affected Products

Blockchain Keystore