PT-2022-15772 · Western Digital+1 · Sweet B Library+1
Published
2022-07-29
·
Updated
2022-08-05
·
CVE-2022-23003
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
No specific software or versions are mentioned in the provided descriptions.
Description
The issue arises when computing a shared secret or point multiplication on the NIST P-256 curve, resulting in an X coordinate of zero. The output is not properly reduced modulo the P-256 field prime, leading to an invalid result. This may cause errors when used in other operations, potentially allowing an attacker to leverage the issue for a limited denial of service targeting individual users. The impact is confined to applications using the affected library and does not extend to other components.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sweet B Library
Sweet B