CVE-2021-43393
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, y J-SIGN a veces permiten a atacantes abusar de la verificación de firmas. Esto está asociado con el algoritmo de firma ECDSA en las plataformas Java Card J-SAFE3 y STSAFE-J que exponen una API Java Card versión 3.0.4. Es explotable para STSAFE-J en configuración cerrada y J-SIGN (cuando la verificación de firmas está activada) pero no para los productos J-SAFE3 EPASS BAC y EAC. También podría afectar a otros productos basados en la plataforma J-SAFE-3 Java Card
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-04 CVE Reserved
- 2022-03-04 CVE Published
- 2024-08-04 CVE Updated
- 2024-11-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.cert.ssi.gouv.fr/avis/CERTFR-2022-AVI-169 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.st.com/s/toparticles | 2022-03-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
St Search vendor "St" | Stsafe-j Firmware Search vendor "St" for product "Stsafe-j Firmware" | 1.1.4 Search vendor "St" for product "Stsafe-j Firmware" and version "1.1.4" | - |
Affected
| in | St Search vendor "St" | Stsafe-j Search vendor "St" for product "Stsafe-j" | - | - |
Safe
|
St Search vendor "St" | J-safe3 Firmware Search vendor "St" for product "J-safe3 Firmware" | 1.2.5 Search vendor "St" for product "J-safe3 Firmware" and version "1.2.5" | - |
Affected
| in | St Search vendor "St" | J-safe3 Search vendor "St" for product "J-safe3" | - | - |
Safe
|