Improper Handling of Length Parameter Inconsistency in mTower - CVE-2022-40757
Published: September 21, 2022
mTower
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of length value in TEE_MACComputeFinal function. A remote attacker can invoke the function TEE_MACComputeFinal with an excessive size value of messageLen and cause a denial of service condition on the target system.