CVE-2015-7940 describes an "invalid curve attack" vulnerability in the Bouncy Castle Java library prior to version 1.51, also affecting products like OpenSUSE and Oracle. The vulnerability stems from the library's failure to validate if a point lies within the elliptic curve during Diffie-Hellman key exchanges. This flaw, rated with a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), allows remote attackers to potentially obtain private keys with low attack complexity and no authentication required. There is no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, nor significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
<= 1.50CPE matchmatch criteria | cpe:2.3:a:bouncycastle:bouncy_castle_crypto_package:*:*:*:*:*:*:*:* | ||
12.5.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:application_testing_suite:12.5.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.