Impact
The mirage-crypto-ec library for OCaml allowed the function Dsa.pub_of_octets for the embedded ECDSA curves P256, P384, and P521 to accept the byte value 0x00, which represents the point at infinity, as a valid public key. Because this point is mathematically equivalent to null, it can be used to forge ECDSA signatures without having a private key, thereby violating the integrity guarantees of systems that rely on these signatures. This is an example of CWE‑295, Improper Certificate Validation, where an invalid key is accepted instead of being rejected. Based on the description, it is inferred that an attacker can craft a public key of 0x00 and use the library to produce signatures that will be accepted as valid by any downstream verification.
Affected Systems
OCaml mirage-crypto-ec library versions prior to 2.2.0 for the ECDSA curve implementations P256, P384, and P521 are impacted.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate impact. EPSS data is not available, so the exact likelihood of exploitation is uncertain; however, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an application that accepts externally supplied ECDSA keys or processes untrusted data, as the flaw permits signature forgery when the crafted key is passed to Dsa.pub_of_octets. The attack requires the attacker to provide the specially crafted public key input, making it a targeted but feasible approach if key validation is absent.
OpenCVE Enrichment