CVE-2019-14318 describes a timing side-channel vulnerability in Crypto++ versions 8.3.0 and earlier, specifically impacting ECDSA signature generation. An attacker, local or remote, can exploit this non-constant time scalar multiplication to deduce the private key by measuring the duration of numerous signing operations. The vulnerability carries a CVSS score of 5.9 (Medium) due to its network attack vector and high impact on confidentiality, despite requiring high attack complexity. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has garnered some community discussion, including mention of a "Minerva Attack" which relates to similar timing side-channels in cryptographic libraries.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.3.0CPE matchmatch criteria | cpe:2.3:a:cryptopp:crypto\+\+:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.