Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2gp-jqv6-cmxg

Опубликовано: 24 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.

A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.

EPSS

Процентиль: 36%
0.00154
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-295

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.

CVSS3: 5.1
redhat
больше 4 лет назад

A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.

CVSS3: 5.5
nvd
больше 3 лет назад

A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.

CVSS3: 5.5
msrc
больше 3 лет назад

A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.

CVSS3: 5.5
debian
больше 3 лет назад

A flaw was found in openCryptoki. The openCryptoki Soft token does not ...

EPSS

Процентиль: 36%
0.00154
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-295