nCipher netHSM Logged Passphrase Information Disclosure Vulnerability
BID:10583
Info
nCipher netHSM Logged Passphrase Information Disclosure Vulnerability
| Bugtraq ID: | 10583 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2004 12:00AM |
| Updated: | Jun 21 2004 12:00AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
nCipher netHSM 2.1 nCipher netHSM 2.0 |
| Not Vulnerable: |
nCipher netHSM 2.1.12 cam5 |
Discussion
nCipher netHSM Logged Passphrase Information Disclosure Vulnerability
It is reported that nCipher's netHSM improperly logs passphrases entered via the netHSM front panel.
Passphrases are improperly logged when entered on the front panel of the netHSM device, either through the built-in thumbwheel or a directly attached keyboard. Under certain configurations, these passphrases are also sent to a remote filesystem.
If an attacker has access to the passphrases, it may aid them in further attacks. Exploitation of the netHSM infrastructure requires physical access to a hardware smartcard, the netHSM device, an acquired passphrase, and access to host data.
If the passphrase is reused in a different context, an attacker may be able to launch further attacks.
A firmware upgrade is available resolving this issue.
It is reported that nCipher's netHSM improperly logs passphrases entered via the netHSM front panel.
Passphrases are improperly logged when entered on the front panel of the netHSM device, either through the built-in thumbwheel or a directly attached keyboard. Under certain configurations, these passphrases are also sent to a remote filesystem.
If an attacker has access to the passphrases, it may aid them in further attacks. Exploitation of the netHSM infrastructure requires physical access to a hardware smartcard, the netHSM device, an acquired passphrase, and access to host data.
If the passphrase is reused in a different context, an attacker may be able to launch further attacks.
A firmware upgrade is available resolving this issue.
Exploit / POC
nCipher netHSM Logged Passphrase Information Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
nCipher netHSM Logged Passphrase Information Disclosure Vulnerability
Solution:
The vendor has released a new firmware version that will not log passphrases under any circumstances.
Affected users are urged to contact the vendor to obtain the required firmware upgrade.
Please see the referenced advisory for further information.
Solution:
The vendor has released a new firmware version that will not log passphrases under any circumstances.
Affected users are urged to contact the vendor to obtain the required firmware upgrade.
Please see the referenced advisory for further information.
References
nCipher netHSM Logged Passphrase Information Disclosure Vulnerability
References:
References:
- nCipher Homepage (nCipher)
- netHSM Home Page (nCipher)
- Security Advisory No. 10: Pass phrases are exposed in netHSM log files (nCipher)