CVE-2023-6258: Latchset PKCS11-Provider

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in a Bleichenbacher-like security flaw, potentially enabling a side-channel attack on PKCS#1 1.5 decryption.

Affected products

  • Latchset PKCS11-Provider: version 0.1 only

Published 2024-01-30. Last modified 2026-06-17.