Vulnerabilities > CVE-2023-6258 - Information Exposure Through Discrepancy vulnerability in Latchset Pkcs11-Provider 0.1

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
latchset
CWE-203

Summary

A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in a Bleichenbacher-like security flaw, potentially enabling a side-channel attack on PKCS#1 1.5 decryption.

Vulnerable Configurations

Part Description Count
Application
Latchset
1

Common Weakness Enumeration (CWE)