← Back

CVE-2022-44310

nvd nist
Published: Feb 24, 2023Modified: Mar 12, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.

Affected (1)

Products: Ecdh Project: Ecdh
1 product
Ecdh
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.2.0

References (2)

Source: cve@mitre.org
ExploitIssue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue Tracking

Timeline

No history available yet.