Vulnerabilities
Vulnerable Software
A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.
CVSS Score
5.9
EPSS Score
0.002
Published
2024-01-31
A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-08-23


Contact Us

Shodan ® - All rights reserved