CVE-2023-50443

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/12/2023
Last modified:
20/12/2023

Description

Encrypted disks created by PRIMX CRYHOD for Windows before Q.2020.4 (ANSSI qualification submission) or CRYHOD for Windows before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger outbound network traffic from computers on which disks are opened.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:primx:cryhod:*:*:*:*:*:*:*:* 2020.4 (excluding)
cpe:2.3:a:primx:cryhod:*:*:*:*:*:*:*:* 2021.0 (including) 2021.3 (excluding)
cpe:2.3:a:primx:cryhod:*:*:*:*:*:*:*:* 2023.0 (including) 2023.5 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*