CVE Feed

    Dashboard / CVE / CVE-2021-43393

    CVE-2021-43393

    STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.

    Published:Mar 4, 2022
    Last Modified:Nov 21, 2024
    EPS:Mar 4, 2022
    EPSS Score:0.00027
    CVSS Score:6.2

    Affected Products

    Vendor
    St
    Product
    J-safe3
    Vendor
    St
    Product
    J-safe3 Firmware
    Vendor
    St
    Product
    Stsafe-j
    Vendor
    St
    Product
    Stsafe-j Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High