The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/tillitis/tkeyclient to version 1.3.0 or higher.
Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm due to an error in the protocol implementation when handling the User Supplied Secret (USS) digest in the LoadApp function. An attacker can cause the Compound Device Identifier (CDI) to be generated as if no USS was provided by supplying a USS digest that begins with a zero byte, resulting in the same key material as if the USS was omitted.
Note: This is only exploitable if the provided USS digest starts with a zero byte.
This vulnerability can be mitigated by choosing a different USS that does not result in a digest beginning with a zero byte.