Improper Handling of Length Parameter Inconsistency in mTower - CVE-2022-40758
Published: September 21, 2022
mTower
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of length value in TEE_CipherUpdate function. A remote attacker can invoke the function TEE_CipherUpdate with an excessive size value of srcLen and cause a denial of service condition on the target system.