Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with duplicate IDs.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Jun/44 | Mailing List Third Party Advisory |
http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html | Technical Description Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-06-30 05:29
Updated : 2017-07-06 10:58
NVD link : CVE-2017-10669
Mitre link : CVE-2017-10669
JSON object : View
CWE
CWE-347
Improper Verification of Cryptographic Signature
Products Affected
xoev
- osci_transport_library