Impact
An analysis of the mirage-crypto-ec package before version 2.4.0 reveals a timing side channel in the implementation of NIST elliptic‑curve scalar multiplication. The execution duration of a lookup operation can vary based on a secret key, allowing an attacker who can measure timing with sufficient precision to infer sensitive values. This weakness could compromise the confidentiality of private keys or other secrets used in cryptographic operations.
Affected Systems
The vulnerability is present in the OCaml mirage-crypto-ec package for all releases prior to 2.4.0. Systems that rely on this library for elliptic‑curve operations, such as secure communication stacks or other cryptographic services written in OCaml, are affected.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. There is no EPSS data, and the vulnerability is not listed in the CISA KEV catalogue. The attack vector is inferred from the nature of the flaw: an adversary would need to observe or influence the timing of scalar multiplication operations, which suggests a local or privileged context unless the service exposes timing data to untrusted parties. The overall risk is moderate, but the potential for key compromise warrants timely remediation.
OpenCVE Enrichment