CVE-2022-32961: HiCOS’ client-side citizen digital certificate - Stack Buffer Overflow
HICOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for token information. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system data or terminate service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32961?
The severity of CVE-2022-32961 is rated medium with a score of 6.8 on the CVSS scale.
How do I fix CVE-2022-32961?
To fix CVE-2022-32961, users should download and install the latest version of the HiCOS client.
What type of vulnerability is identified in CVE-2022-32961?
CVE-2022-32961 is a stack buffer overflow vulnerability related to insufficient parameter length validation.
Who can exploit the CVE-2022-32961 vulnerability?
An unauthenticated physical attacker can exploit the CVE-2022-32961 vulnerability to execute arbitrary code.
On which platforms does CVE-2022-32961 affect the HiCOS client?
CVE-2022-32961 affects the HiCOS Natural Person Credential Component Client on Linux, MacOS, and Windows platforms.