CVE-2022-29185 affects the totp-rs Rust library, which is used for generating time-based one-time passwords (TOTP). Prior to version 1.1.0, the library's token comparison was not constant-time, creating a theoretical side-channel vulnerability. This medium-severity vulnerability (CVSS 4.4) requires high privileges and a high attack complexity, as an attacker would need to know the user's password beforehand to potentially guess TOTP tokens. There is no evidence of active exploitation, no known exploit code, and minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.0CPE matchmatch criteria | cpe:2.3:a:totp-rs_project:totp-rs:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.