CVE-2023-36199: Null Pointer Dereference
Published Aug 25, 2023
·Updated
An issue in skalenetwork sgxwallet v.1.9.0 and below allows an attacker to cause a denial of service via the trustedGenerateEcdsaKey component.
Affected Software
1 affected component
SKALE sgxwallet<=1.9.0
Event History
Aug 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-36199?
The severity of CVE-2023-36199 is high with a score of 7.5.
2
How does CVE-2023-36199 affect skalenetwork sgxwallet?
CVE-2023-36199 allows an attacker to cause a denial of service in skalenetwork sgxwallet v.1.9.0 and below.
3
How can an attacker exploit CVE-2023-36199?
An attacker can exploit CVE-2023-36199 by using the trustedGenerateEcdsaKey component to cause a denial of service.
4
Is there a fix available for CVE-2023-36199?
Yes, upgrading to version 1.9.1 or above of skalenetwork sgxwallet will fix the issue.
5
Where can I find more information about CVE-2023-36199?
More information about CVE-2023-36199 can be found at the following link: https://github.com/skalenetwork/sgxwallet/issues/419