VYPR
Unrated severityNVD Advisory· Published Jun 25, 2024· Updated Aug 29, 2024

Use of a Key Past its Expiration Date in Conduit

CVE-2024-6299

Description

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.