#VU64732 Improper Verification of Cryptographic Signature in ecdsa-dotnet - CVE-2021-43569
Published: June 28, 2022
ecdsa-dotnet
STARK BANK
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) fails to check that the signature is non-zero. A remote unauthenticated attacker can forge signatures on arbitrary messages to execute arbitrary code on the target system.