PT-2013-1372 · Nist · Dual Ec Drbg

Dan Shumow

+1

·

Publicado

2013-10-11

·

Atualizado

2022-11-01

·

CVE-2007-6755

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dual Elliptic Curve Deterministic Random Bit Generation (Dual EC DRBG) algorithm (affected versions not specified)
Description The Dual Elliptic Curve Deterministic Random Bit Generation algorithm contains point Q constants that may have a relationship to certain "skeleton key" values. This could allow attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6755

Produtos afetados

Dual Ec Drbg