Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1) execute arbitrary code on a client or (2) forge messages to the server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Class_5_enterprise_vulnerability_management | Secure_elements | 2.8.0 (including) | 2.8.0 (including) |