CVE-2021-3798
—CVSS 3.1
5.5 medium
EPSS
<1%p20
Published
()
Modified
Description
A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.
- Vendors
- opencryptoki project
- Products
- opencryptoki
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.