169
VMScore

CVE-2018-12433

Published: 15/06/2018 Updated: 17/05/2024
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.9 | Impact Score: 4 | Exploitability Score: 0.5
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

cryptlib up to and including 3.4.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host. NOTE: the vendor does not include side-channel attacks within its threat model

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cryptlib cryptlib