CVE-2021-41117 affects the keypair_project keypair library, a JavaScript RSA key generator, due to critical flaws in its random number generation. The library's fallback random number generator, used when a strong Cryptographically Secure Pseudorandom Number Generator (CSPRNG) is unavailable (especially in NodeJS environments), incorrectly encodes seed data, leading to a high probability of zero bytes. This results in the generation of easily guessable and identical RSA keys, posing a significant risk of unauthorized access or decryption of confidential information. With a CVSS score of 9.1 (CRITICAL), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction. The potential impact is high for confidentiality and integrity, as attackers could decrypt messages or gain unauthorized access. The FAUCET Risk Score is 72/100, indicating a substantial threat. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. While community discussion is limited with only one mention, media coverage includes one article from hackernews, suggesting some awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.4CPE matchmatch criteria | cpe:2.3:a:keypair_project:keypair:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.