Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with duplicate IDs.
                
            References
                    | Link | Resource | 
|---|---|
| http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html | Technical Description Third Party Advisory | 
| http://seclists.org/fulldisclosure/2017/Jun/44 | Mailing List Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2017-06-30 12:29
Updated : 2017-07-06 17:58
NVD link : CVE-2017-10669
Mitre link : CVE-2017-10669
CVE.ORG link : CVE-2017-10669
JSON object : View
Products Affected
                xoev
- osci_transport_library
 
CWE
                
                    
                        
                        CWE-347
                        
            Improper Verification of Cryptographic Signature
