First published: Wed Jul 22 2015(Updated: )
The Gemalto SafeNet Luna HSM allows remote authenticated users to bypass intended key-export restrictions by leveraging (1) crypto-user or (2) crypto-officer access to an HSM partition.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gemalto Safenet Luna G5 | ||
Gemalto Safenet Luna SA | ||
Gemalto Safenet Luna SA |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5464 has a high severity rating due to its ability to allow remote authenticated users to bypass key-export restrictions.
To fix CVE-2015-5464, it is recommended to apply the latest security updates provided by Gemalto for the affected SafeNet Luna HSM products.
The affected systems include various models of Gemalto SafeNet Luna HSM such as Luna G5, Luna PCI-e, and Luna SA.
Both crypto-users and crypto-officers can exploit CVE-2015-5464 to bypass key-export restrictions within an HSM partition.
Yes, CVE-2015-5464 is considered critical due to the implications for key management and data security in affected systems.