ZeroHour

CVE-2022-44310

PoC
CVSS 3.1
7.5 high
EPSS
<1%p50
Published
()
Modified
Description

In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.

Vendors
ecdh project
Products
ecdh
Weakness
CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.