CVE-2023-32690 affects libspdm versions prior to 2.3.3 and 3.0, where a Requester fails to validate the Responder's CTExponent after a successful CAPABILITIES response. This allows an unvalidated CTExponent to be used in timeout calculations for cryptographic operations, potentially leading to a denial-of-service. Rated with a CVSS score of 7.5 (High), this vulnerability has a network attack vector and low attack complexity, with the primary impact being high availability disruption. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE. Patches are available in versions 2.3.3 and 3.0, and a workaround involves the Requester checking the Responder's CTExponent after VCA completion and terminating communication if it is 64 or greater.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.3CPE matchmatch criteria | cpe:2.3:a:dmtf:libspdm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.