Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ before 11.72 allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key [KNETI] and impersonate the nShield Connect device on a network, affect the integrity and confidentiality of newly created keys, and potentially cause other unspecified impacts using previously loaded keys by connecting to the USB port on the front panel.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1878
Reference (s):
- SECTRACK:1032152
- URL: http://www.securitytracker.com/id/1032152

