CVE-2022-32959: HiCOS’ client-side citizen digital certificate - Stack Buffer Overflow
HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for OS information. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system data or terminate service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32959?
CVE-2022-32959 has a medium severity rating of 6.8 according to the CVSS 3.1 metrics.
How can I fix CVE-2022-32959?
To fix CVE-2022-32959, download and install the latest version of the HiCOS client.
What type of vulnerability is CVE-2022-32959?
CVE-2022-32959 is a stack buffer overflow vulnerability related to insufficient parameter length validation.
Who can exploit CVE-2022-32959?
An unauthenticated physical attacker can exploit CVE-2022-32959 to execute arbitrary code.
What software is affected by CVE-2022-32959?
CVE-2022-32959 affects the HiNet Hicos Natural Person Credential Component Client on Linux, MacOS, and Windows.