A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-27058 A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-03T17:09:09.595Z

Reserved: 2021-09-13T00:00:00

Link: CVE-2021-3798

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-23T16:15:09.930

Modified: 2024-11-21T06:22:27.943

Link: CVE-2021-3798

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-05-18T00:00:00Z

Links: CVE-2021-3798 - Bugzilla

cve-icon OpenCVE Enrichment

No data.