Description
The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to version 1.0.24.0318 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38584 | The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it. |
References
History
Fri, 09 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Changingtec
Changingtec tcb Servisign |
|
| CPEs | cpe:2.3:a:changingtec:tcb_servisign:*:*:*:*:*:windows:*:* | |
| Vendors & Products |
Changingtec
Changingtec tcb Servisign |
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-02T15:30:54.622Z
Reserved: 2024-07-09T03:30:54.516Z
Link: CVE-2024-40719
No data.
Status : Analyzed
Published: 2024-08-02T10:16:00.470
Modified: 2024-08-09T14:36:32.300
Link: CVE-2024-40719
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD