Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2023-32690

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
01/06/2023
Última modificación:
09/06/2023

Descripción

*** Pendiente de traducción *** libspdm is a sample implementation that follows the DMTF SPDM specifications. Prior to versions 2.3.3 and 3.0, following a successful CAPABILITIES response, a libspdm Requester stores the Responder&amp;#39;s CTExponent into its context without validation. If the Requester sends a request message that requires a cryptography operation by the Responder, such as CHALLENGE, libspdm will calculate the timeout value using the Responder&amp;#39;s unvalidated CTExponent.<br /> <br /> A patch is available in version 2.3.3. A workaround is also available. After completion of VCA, the Requester can check the value of the Responder&amp;#39;s CTExponent. If it greater than or equal to 64, then the Requester can stop communication with the Responder.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:dmtf:libspdm:*:*:*:*:*:*:*:* 2.3.3 (excluyendo)