Use of a broken or risky cryptographic algorithm in MDLC - CVE-2022-30273

 

Use of a broken or risky cryptographic algorithm in MDLC - CVE-2022-30273

Published: June 29, 2022


Vulnerability identifier: #VU64790
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-30273
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to use of a broken or risky cryptographic algorithm. A remote attacker can use specially crafted messages with ciphertext blocks inserted at certain positions, leading to message manipulation or exposure of the attack surface of the MDLC protocol parser to memory corruption attacks.


Affected software

MDLC

How to mitigate CVE-2022-30273

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins