Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-28498

Опубликовано: 02 фев. 2021
Источник: nvd
CVSS3: 6.8
CVSS2: 4.3
EPSS Низкий

Описание

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:indutny:elliptic:*:*:*:*:*:node.js:*:*
Версия до 6.5.4 (исключая)

EPSS

Процентиль: 64%
0.00473
Низкий

6.8 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 5 лет назад

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.

CVSS3: 6.8
debian
около 5 лет назад

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issu ...

CVSS3: 6.8
github
почти 5 лет назад

Elliptic Uses a Broken or Risky Cryptographic Algorithm

EPSS

Процентиль: 64%
0.00473
Низкий

6.8 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-327