Vulnerabilità ed exploit · Furto di credenziali
La rottura è nella fiducia, non solo nella matematica delle firme. Szafir SDK può restituire un risultato di verifica pulito anche quando non può dimostrare che il certificato del firmatario sia attendibile, quindi le applicazioni che si affidano a quel risultato possono accettare un’identità che non hanno mai realmente convalidato.
1 fonte · 25 mag
CERT Polska
Vulnerability in Szafir SDK software
Improper Certificate Verification vulnerability (CVE-2026-9058) has been found in Szafir SDK software.
originalePart of the PlainSec briefing for 2026-05-25
Every edition of this story: Szafir SDK Firme Non Attendibili Trattate come Verificate