Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attackers to send messages to a protected asset without knowing the proper CEID.
Name | Vendor | Start Version | End Version |
---|---|---|---|
C5_enterprise_vulnerability_management | Secure_elements | * | * |