Lucene search

K
redosRedosROS-20230417-04
HistoryApr 17, 2023 - 12:00 a.m.

ROS-20230417-04

2023-04-1700:00:00
redos.red-soft.ru
27
vulnerability
cryptoprocessor
tpm
unauthorized access
buffer boundaries
arbitrary code
denial of service
exploitation
memory

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

20.5%

A vulnerability in the CryptParameterDecryption function of the cryptoprocessor firmware of the Trusted
Platform Module (TPM) is related to reading data beyond buffer boundaries in memory. Exploitation of the vulnerability
may allow an intruder to gain unauthorized access to protected information

Vulnerability of CryptParameterDecryption function in the firmware of the cryptoprocessor Trusted
Platform Module (TPM) is related to writing beyond buffer boundaries in memory. Exploitation of the vulnerability could
allow an attacker to cause a denial of service or execute arbitrary code.

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64libtpms<Β 0.9.6-1UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

20.5%