First published: Thu May 04 2023(Updated: )
Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Blockchain Keystore | <1.3.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21511 is categorized as a moderate severity vulnerability due to its potential to allow local attackers to read arbitrary memory.
To remediate CVE-2023-21511, users should update the Samsung Blockchain Keystore to version 1.3.12.1 or later.
CVE-2023-21511 affects all versions of Samsung Blockchain Keystore prior to 1.3.12.1.
CVE-2023-21511 is an out-of-bounds read vulnerability that occurs while processing specific commands in the Samsung Blockchain Keystore.
CVE-2023-21511 can be exploited by local attackers who have access to the vulnerable Samsung Blockchain Keystore.