PT-2025-2037 · Openssl+10 · Openssl+10

Alicja Kario

+2

·

Published

2025-01-20

·

Updated

2026-04-27

·

CVE-2024-13176

CVSS v2.0

4.3

Medium

VectorAV:L/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves, in particular the NIST P-521 curve. The severity of this vulnerability is Low.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:15699
ALSA-2025:16046
AZL-55889
AZL-55894
AZL-56010
AZL-78537
BDU:2025-03280
CVE-2024-13176
DLA-4176-1
ECHO-E857-6D70-7368
INFSA-2025_16046
JLSEC-2026-248
MGASA-2025-0025
MGASA-2025-0101
MGASA-2025-0210
OESA-2025-1190
OESA-2025-1191
OESA-2025-1192
OESA-2025-1193
OESA-2025-1194
OESA-2025-1287
OESA-2025-1288
OPENSUSE-SU-2025:14696-1
OPENSUSE-SU-2025_0345-1
OPENSUSE-SU-2025_0349-1
OPENSUSE-SU-2025_0387-1
OPENSUSE-SU-2025_0388-1
OPENSUSE-SU-2025_0430-1
OPENSUSE-SU-2025_0613-1
RHSA-2025_16046
SUSE-SU-2025:02042-1
SUSE-SU-2025:0345-1
SUSE-SU-2025:0349-1
SUSE-SU-2025:0356-1
SUSE-SU-2025:0387-1
SUSE-SU-2025:0388-1
SUSE-SU-2025:0390-1
SUSE-SU-2025:0430-1
SUSE-SU-2025:0613-1
SUSE-SU-2025:0613-2
SUSE-SU-2025:0613-3
SUSE-SU-2025:20233-1
SUSE-SU-2025:20406-1
SUSE-SU-2025:20464-1
SUSE-SU-2025_02042-1
SUSE-SU-2025_0345-1
SUSE-SU-2025_0349-1
SUSE-SU-2025_0356-1
SUSE-SU-2025_0387-1
SUSE-SU-2025_0388-1
SUSE-SU-2025_0390-1
SUSE-SU-2025_0430-1
SUSE-SU-2025_0613-1
SUSE-SU-2025_0613-2
SUSE-SU-2025_0613-3
USN-7264-1
USN-7278-1
USN-7894-1
USN-7894-2

Affected Products

Almalinux
Astra Linux
Debian
Ibm Aix
Linuxmint
Mysql Server
Openssl
Red Hat
Red Os
Suse
Ubuntu