CVE-2022-32959 is a stack-based buffer overflow vulnerability in the HiCOS client-side digital certificate component, specifically affecting the hinet hicos_natural_person_credential_component_client. This flaw arises from insufficient parameter length validation when reading IC card OS information. An unauthenticated physical attacker can exploit this with low complexity to execute arbitrary code, manipulate system data, or cause a denial of service, resulting in high confidentiality, integrity, and availability impacts. While rated Medium severity (CVSS 6.8), there is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.3.30306CPE matchmatch criteria | cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30306:*:*:*:*:linux:*:* | ||
3.0.3.30404CPE matchmatch criteria | cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30404:*:*:*:*:macos:*:* | ||
3.1.0.00002CPE matchmatch criteria | cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.1.0.00002:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.