nCipher PKCS#11 Implementation Access Control Vulnerability
BID:6448
Info
nCipher PKCS#11 Implementation Access Control Vulnerability
| Bugtraq ID: | 6448 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Dec 20 2002 12:00AM |
| Updated: | Dec 20 2002 12:00AM |
| Credit: | Announced by nCipher. |
| Vulnerable: |
nCipher SafeBuilder nCipher payShield nCipher nShield nCipher nForce nCipher MSCAPI CSP 5.54 nCipher MSCAPI CSP 5.50 |
| Not Vulnerable: | |
Discussion
nCipher PKCS#11 Implementation Access Control Vulnerability
A vulnerability has been reported in the nCipher implementation of PKCS#11. Under certain circumstances, it is possible for plaintext keys to be exported from affected devices and components. This is due to a flaw in the access control component of the nCipher PKCS#11 library.
A vulnerability has been reported in the nCipher implementation of PKCS#11. Under certain circumstances, it is possible for plaintext keys to be exported from affected devices and components. This is due to a flaw in the access control component of the nCipher PKCS#11 library.
Exploit / POC
nCipher PKCS#11 Implementation Access Control Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
nCipher PKCS#11 Implementation Access Control Vulnerability
Solution:
A patch kit is available from nCipher. Please contact nCipher support to obtain it.
Solution:
A patch kit is available from nCipher. Please contact nCipher support to obtain it.
References
nCipher PKCS#11 Implementation Access Control Vulnerability
References:
References:
- Access control defects in PKCS#11 keys (nCipher)