SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-2197

HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms.

LOW 2.5EPSS 0.09%

Does this matter?

Lower severity and a low EPSS score (0.09%). Track it; it rarely justifies an emergency change on its own.

Description

HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key. Fixed in 1.13.2

CVSS 3.1
2.5 LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.09% probability · 0th percentile
CISA KEV
Not listed
Weakness
CWE-326
Affected
hashicorp/vault
Source
security@hashicorp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.