SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-1945

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it…

LOW 2.6EPSS 3.29%

Does this matter?

Lower severity and a low EPSS score (3.29%). Track it; it rarely justifies an emergency change on its own.

Description

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS
3.29% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
openssl/openssl
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.