CVE-2021-37587 Information
Jun 07, 2022
cve
Description
In Charm 0.43 any single user can decrypt DAC-MACS or MA-ABE-YJ14 data.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://www2.hci.uni-hannover.de/papers/Tan2019.pdf https://github.com/JHUISI/charm/issues/276 https://jhuisi.github.io/charm/charm/schemes/abenc/abenc_dacmacs_yj14.html https://jhuisi.github.io/charm/_modules/abenc_maabe_yj14.html https://eprint.iacr.org/2020/460
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: