CVE-2021-43393
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.
Published:Mar 4, 2022
Last Modified:Nov 21, 2024
EPS:Mar 4, 2022
EPSS Score:0.00027
CVSS Score:6.2
Affected Products
Vendor
Product
Action
Vendor
St
Product
J-safe3
St
J-safe3
Vendor
St
Product
J-safe3 Firmware
St
J-safe3 Firmware
Vendor
St
Product
Stsafe-j
St
Stsafe-j
Vendor
St
Product
Stsafe-j Firmware
St
Stsafe-j Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
