VYPR

Asp

by Centra

CVEs (4)

  • CVE-2023-20599HigJun 10, 2025
    risk 0.51cvss 7.9epss 0.00

    Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86 resulting in potential loss of control of cryptographic key pointer/index leading to loss of integrity or confidentiality.

  • CVE-2023-20516LowSep 6, 2025
    risk 0.21cvss 3.3epss 0.00

    Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Registers (TMRs) potentially resulting in loss of confidentiality or integrity.

  • CVE-2023-31326LowSep 6, 2025
    risk 0.18cvss 2.8epss 0.00

    Use of an uninitialized variable in the ASP could allow an attacker to access leftover data from a trusted execution environment (TEE) driver, potentially leading to loss of confidentiality.

  • CVE-2001-1550Dec 31, 2001
    risk 0.00cvss epss 0.00

    CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.