CVE-2018-12438 describes a memory-cache side-channel vulnerability in the Elliptic Curve Cryptography library (libsunec), allowing for a Return Of the Hidden Number Problem (ROHNP) attack on ECDSA signatures. This medium-severity vulnerability (CVSS 4.9) requires an attacker to have physical access to the local machine or be on the same physical host as a different virtual machine. While it could lead to the discovery of an ECDSA key, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:libsunec_project:libsunec:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.