CVE-2023-6258
Latchset Pkcs11-Provider 0.1
Raw vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2023-6258 is a high-severity Improper Protection of Physical Side Channels (CWE-1300) vulnerability in Latchset Pkcs11-Provider. Its CVSS base score is 8.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Account Discovery (T1087); ranked at the 44th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to IA-6 (Authentication Feedback) and SI-11 (Error Handling) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-58503
Vulnerability Data
A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in a Bleichenbacher-like security flaw, potentially enabling a side-channel attack on PKCS#1 1.5 decryption.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 3 hardening rules · 2 OS baselines
—
Mitigating Controls (NIST 800-53 r5) AI
Obscures authentication feedback so that success/failure differences are not observable to attackers.
Requires error messages to avoid revealing exploitable details, directly stopping observable response discrepancies.
Directly requires protection against electromagnetic emanation leakage, which stops one class of the physical side-channel exposures described in CWE-1300.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent observable response discrepancies via consistent error handling and timing.
Limiting physical access reduces opportunity for side-channel observation but does not address emission-protection mechanisms inside the device.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Physical perimeters can limit attacker proximity needed for side-channel capture.
Entry controls reduce opportunities for physical observation of emissions.
Securing rooms and facilities can shield equipment from side-channel probing.
Monitoring deters or detects attempts to exploit physical side channels.
Protecting against physical threats can include shielding against emanation attacks.
Proper siting and protection of equipment can reduce observable emissions.