Skip to main content

Use of a Key Past its Expiration Date

CVE-2025-48813

Severity Medium
Score 6.3/10

Summary

Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.

  • HIGH
  • LOCAL
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-324 - Use of a Key Past its Expiration Date

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

References

Advisory Timeline

  • Published