CVE-2023-31127 is a high-severity vulnerability in libspdm versions prior to 2.3.1, affecting SPDM responders that support both DHE and PSK sessions with mutual authentication. An attacker can bypass mutual authentication by initiating a session with one method (e.g., DHE) and completing it with another (e.g., PSK_FINISH), leading to high impact on confidentiality, integrity, and availability. The attack is network-based with low complexity and requires low privileges. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.2CPE matchmatch criteria | cpe:2.3:a:dmtf:libspdm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.