CVE-2021-42023

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
14/12/2021
Last modified:
20/12/2021

Description

A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affected applications insufficiently protects the built-in private keys that are required to decrypt electronic intellectual property (IP) data in accordance with the IEEE 1735 recommended practice. This could allow a sophisticated attacker to discover the keys, bypassing the protection intended by the IEEE 1735 recommended practice.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:siemens:modelsim:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:questa:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools