CVE-2022-44310

In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.
References
Link Resource
https://github.com/developmentil/ecdh/issues/3 Exploit Issue Tracking
https://github.com/developmentil/ecdh/issues/3 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:ecdh_project:ecdh:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 07:27

Type Values Removed Values Added
References () https://github.com/developmentil/ecdh/issues/3 - Exploit, Issue Tracking () https://github.com/developmentil/ecdh/issues/3 - Exploit, Issue Tracking
Summary
  • (es) En Development IL ecdh anterior a 0.2.0, un atacante puede enviar un punto no válido (no en la curva) como clave pública y obtener el secreto compartido derivado.

07 Mar 2023, 02:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://github.com/developmentil/ecdh/issues/3 - (MISC) https://github.com/developmentil/ecdh/issues/3 - Exploit, Issue Tracking
CPE cpe:2.3:a:ecdh_project:ecdh:*:*:*:*:*:node.js:*:*
CWE CWE-668

24 Feb 2023, 23:48

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-24 20:15

Updated : 2024-11-21 07:27


NVD link : CVE-2022-44310

Mitre link : CVE-2022-44310

CVE.ORG link : CVE-2022-44310


JSON object : View

Products Affected

ecdh_project

  • ecdh
CWE
CWE-668

Exposure of Resource to Wrong Sphere