CVE-2024-1544 describes a side-channel vulnerability in wolfSSL's ECDSA nonce generation, specifically affecting the SECP160R1 curve. An attacker can observe control-flow revealing side-channels during the modular reduction of the random number 'r' to derive 'k', revealing a bias in the most significant bits of 'k'. This vulnerability has a CVSS score of 4.9 (MEDIUM), indicating a high confidentiality impact for an attacker with high privileges over the network. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 5.6.4CPE match | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* | ||
< 5.7.2CPE matchmatch criteria | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.