Man-in-the-middle vulnerability in Arm AArch64 Cryptographic Library
CVE-2023-26084

3.7LOW

Key Information:

Vendor

Arm

Vendor
CVE Published:
15 March 2023

What is CVE-2023-26084?

The AArch64cryptolib API, specifically armv8_dec_aes_gcm_full(), is vulnerable due to an improperly initialized variable that does not verify the authentication tag of AES-GCM protected data. This flaw can lead to potential man-in-the-middle attacks, compromising the integrity of sensitive information. Users of the affected library versions should apply the necessary patches to safeguard their systems from exploitation, as the failure in authentication validation poses a serious risk to data security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.