The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it.
Solution:
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-7964-5b266-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-7970-e8ac5-2.html | third party advisory |