漏洞标题
Alpine Halo9加密签名验证不当漏洞
漏洞描述信息
Alpine Halo9 存在不当验证加密签名漏洞。此漏洞允许物理接近的攻击者绕过受影响的Alpine Halo9设备上的签名验证机制。利用此漏洞无需身份验证。
具体缺陷存在于固件元数据签名验证机制中。问题源于未能正确验证加密签名。攻击者可以利用此漏洞结合其他漏洞以root权限执行任意代码。
参考编号:ZDI-CAN-23102
CVSS信息
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
密码学签名的验证不恰当
漏洞标题
Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability
漏洞描述信息
Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically present attackers to bypass signature validation mechanism on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the firmware metadata signature validation mechanism. The issue results from the lack of proper verification of a cryptographic signature. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.
Was ZDI-CAN-23102
CVSS信息
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
漏洞类别
密码学签名的验证不恰当
漏洞标题
Alpine Halo9 安全漏洞
漏洞描述信息
Alpine Halo9是Alpine公司的一款多媒体播放器。 Alpine Halo9存在安全漏洞,该漏洞源于加密签名验证不当。
CVSS信息
N/A
漏洞类别
其他