CVE-2023-2197

Published May 1, 2023

Last updated a year ago

Overview

Description
HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key. Fixed in 1.13.2
Source
security@hashicorp.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
2.5
Impact score
1.4
Exploitability score
1
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

Weaknesses

nvd@nist.gov
CWE-326
security@hashicorp.com
CWE-326

Social media

Hype score
Not currently trending

Configurations