Improper Verification of Cryptographic Signature in ecdsa-dotnet - CVE-2021-43569
Published: June 28, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) fails to check that the signature is non-zero. A remote unauthenticated attacker can forge signatures on arbitrary messages to execute arbitrary code on the target system.
Affected software
IBM Robotic Process Automation
How to mitigate CVE-2021-43569
IBM Robotic Process Automation - update to 21.0.1.5