CVE-2020-12607 describes a vulnerability in fastecdsa versions prior to 2.1.2, specifically affecting its ECDSA implementation when using the NIST P-256 curve. The flaw involves mishandling of the point at infinity, causing legitimate signatures to fail verification under specific, extreme conditions. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity and no user interaction required. While it does not directly lead to confidentiality or integrity compromise, an attacker could potentially exploit this to cause denial of service or disrupt systems by targeting users whose signatures would fail verification. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or perceived threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.2CPE matchmatch criteria | cpe:2.3:a:antonkueltz:fastecdsa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.