Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-7511

11
FAUCET Score

CVE-2015-7511 describes a vulnerability in Libgcrypt versions prior to 1.6.5, affecting various Canonical, Debian, and GnuPG products. This flaw involves improper elliptic-point curve multiplication during decryption, which could allow physically proximate attackers to extract ECDH keys. The vulnerability has a low severity CVSS score of 2.0, requiring physical access and high attack complexity, with a potential impact of information disclosure. There is no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.6.4CPE matchmatch criteria
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 3.0

2.0LOW

CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
0.5
Impact Score
1.4
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 100th percentile among its peer group of 20 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (2)

microsoft2016-Apr/CVE-2015-7511Low

Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.

Apr 12, 2016
redhatCVE-2015-7511Low

libgcrypt: side-channel attack on ECDH with Weierstrass curves

Feb 8, 2016

References

lists.opensuse.org / opensuse-updates/2016-05/msg00027.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/W2IL4PAEICHGA2XMQYRY3MIWHM4GMPAG
lists.gnupg.org / pipermail/gnupg-announce/2016q1/000384.html
Vendor Advisory
security.gentoo.org / glsa/201610-04
cs.tau.ac.il / ~tromer/ecdh
debian.org / security/2016/dsa-3474
debian.org / security/2016/dsa-3478
securityfocus.com / bid/83253
ubuntu.com / usn/USN-2896-1