7.5

CVE-2023-24533

Incorrect multiplication of unreduced P-256 scalars in filippo.io/nistec

Multiplication of certain unreduced P-256 scalars produce incorrect results. There are no protocols known at this time that can be attacked due to this.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nistec Project ≫ Nistec SwPlatform go Version < 0.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.473
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-682 Incorrect Calculation

The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

https://go.dev/issue/58647
Patch
Issue Tracking
https://github.com/FiloSottile/nistec/commit/c58aa1223ccf3943513e1e661cebce95af137244
Patch
https://pkg.go.dev/vuln/GO-2023-1595
Third Party Advisory