A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.
                
            References
                    | Link | Resource | 
|---|---|
| https://access.redhat.com/security/cve/CVE-2021-3798 | Third Party Advisory | 
| https://bugzilla.redhat.com/show_bug.cgi?id=1990591 | Issue Tracking Patch Third Party Advisory | 
| https://github.com/opencryptoki/opencryptoki/commit/4e3b43c3d8844402c04a66b55c6c940f965109f0 | Patch Third Party Advisory | 
| https://github.com/opencryptoki/opencryptoki/pull/402 | Patch Third Party Advisory | 
| https://access.redhat.com/security/cve/CVE-2021-3798 | Third Party Advisory | 
| https://bugzilla.redhat.com/show_bug.cgi?id=1990591 | Issue Tracking Patch Third Party Advisory | 
| https://github.com/opencryptoki/opencryptoki/commit/4e3b43c3d8844402c04a66b55c6c940f965109f0 | Patch Third Party Advisory | 
| https://github.com/opencryptoki/opencryptoki/pull/402 | Patch Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 06:22
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://access.redhat.com/security/cve/CVE-2021-3798 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=1990591 - Issue Tracking, Patch, Third Party Advisory | |
| References | () https://github.com/opencryptoki/opencryptoki/commit/4e3b43c3d8844402c04a66b55c6c940f965109f0 - Patch, Third Party Advisory | |
| References | () https://github.com/opencryptoki/opencryptoki/pull/402 - Patch, Third Party Advisory | 
10 Jul 2023, 19:34
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | NVD-CWE-Other | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 5.5 | 
| CPE | cpe:2.3:a:opencryptoki_project:opencryptoki:*:*:*:*:*:*:*:* | |
| References | (MISC) https://access.redhat.com/security/cve/CVE-2021-3798 - Third Party Advisory | |
| References | (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1990591 - Issue Tracking, Patch, Third Party Advisory | |
| References | (MISC) https://github.com/opencryptoki/opencryptoki/commit/4e3b43c3d8844402c04a66b55c6c940f965109f0 - Patch, Third Party Advisory | |
| References | (MISC) https://github.com/opencryptoki/opencryptoki/pull/402 - Patch, Third Party Advisory | 
23 Aug 2022, 17:04
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-08-23 16:15
Updated : 2024-11-21 06:22
NVD link : CVE-2021-3798
Mitre link : CVE-2021-3798
CVE.ORG link : CVE-2021-3798
JSON object : View
Products Affected
                opencryptoki_project
- opencryptoki
CWE
                