CVE-2023-2197

Published May 1, 2023

Last updated 24 days ago

Overview

Description
HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key. Fixed in 1.13.2
Source
security@hashicorp.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
2.5
Impact score
1.4
Exploitability score
1
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

Weaknesses

security@hashicorp.com
CWE-326
nvd@nist.gov
CWE-326
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-326

Social media

Hype score
Not currently trending

Configurations