CVE-2022-32960: HiCOS’ client-side citizen digital certificate - Stack Buffer Overflow
Published Jul 20, 2022
·Updated
HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for card number. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system data or terminate service.
Affected Software
3 affected components
HiNet Hicos Natural Person Credential Component Client Linux=3.0.3.30306
HiNet Hicos Natural Person Credential Component Client Macos=3.0.3.30404
HiNet Hicos Natural Person Credential Component Client Windows=3.1.0.00002
Remediation
Information
Download latest version
Event History
Jul 20, 2022
CVE Published
via MITRE·02:02 AM
Data Sourced
via MITRE·02:02 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-32960?
CVE-2022-32960 has a medium severity rating of 6.8 on the CVSS scale.
2
How do I fix CVE-2022-32960?
To fix CVE-2022-32960, download the latest version of the HiCOS client software.
3
What component is affected by CVE-2022-32960?
CVE-2022-32960 affects the client-side citizen digital certificate component of HiCOS.
4
What type of vulnerability is CVE-2022-32960?
CVE-2022-32960 is a stack-based buffer overflow vulnerability.
5
Who can exploit CVE-2022-32960?
An unauthenticated physical attacker can exploit the CVE-2022-32960 vulnerability.