CVE-2021-40855: Critical severity europa technical specifications for digital covid certificates vulnerability
Published Jan 21, 2022
·Updated
The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.
Affected Software
1 affected component
Europa Technical Specifications For Digital Covid Certificates<1.1
Event History
Jan 21, 2022
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-40855?
CVE-2021-40855 is classified as a moderate severity vulnerability due to improper handling of non-production public key certificates.
2
How do I fix CVE-2021-40855?
To remediate CVE-2021-40855, ensure that only production-ready public key certificates are used in production environments.
3
What software is affected by CVE-2021-40855?
CVE-2021-40855 affects the Europa Technical Specifications for Digital COVID Certificates versions prior to 1.1.
4
What potential impact does CVE-2021-40855 have?
The vulnerability could lead to unauthorized access or misuse of the digital certificates in production environments.
5
Are there any known exploits for CVE-2021-40855?
As of now, there are no known public exploits targeting CVE-2021-40855.