PT-2022-15772 · Western Digital+1 · Sweet B Library+1

Published

2022-07-29

·

Updated

2022-08-05

·

CVE-2022-23003

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue arises when computing a shared secret or point multiplication on the NIST P-256 curve, resulting in an X coordinate of zero. The output is not properly reduced modulo the P-256 field prime, leading to an invalid result. This may cause errors when used in other operations, potentially allowing an attacker to leverage the issue for a limited denial of service targeting individual users. The impact is confined to applications using the affected library and does not extend to other components.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2022-23003

Affected Products

Sweet B Library
Sweet B