CVE-2022-47931

CRITICAL

Iofinnet Tss-lib < 2.0.0 - Weak Encryption

Title source: rule
STIX 2.1

Description

IO FinNet tss-lib before 2.0.0 allows a collision of hash values.

Scores

CVSS v3 9.1
EPSS 0.0020
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-326
Status published
Products (2)
bnb-chain/tss-lib 0 - 1.3.6-0.20230324145555-bb6fb30bd3ebGo
iofinnet/tss-lib < 2.0.0
Published Dec 23, 2022
Tracked Since Feb 18, 2026