PT-2013-1372 · Nist · Dual Ec Drbg

Dan Shumow

+1

·

Published

2013-10-11

·

Updated

2022-11-01

·

CVE-2007-6755

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dual Elliptic Curve Deterministic Random Bit Generation (Dual EC DRBG) algorithm (affected versions not specified)
Description The Dual Elliptic Curve Deterministic Random Bit Generation algorithm contains point Q constants that may have a relationship to certain "skeleton key" values. This could allow attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2007-6755

Affected Products

Dual Ec Drbg