Iofinnet's vulnerability profile centers on its threshold-signature library (TSS-lib), a cryptographic component used in distributed key management and blockchain applications, with observed weaknesses spanning authentication and encryption implementation. The durable signal reflects the inherent challenges of secure cryptographic protocol design, where vulnerabilities recur in areas such as observable timing discrepancies, capture-replay authentication flaws, and inadequate encryption strength. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iofinnet over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47931CRITICAL IO FinNet tss-lib before 2.0.0 allows a collision of hash values. | Dec 23, 2022 | 9.1 | 28 | NO | NO |
CVE-2023-26556CRITICAL io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implementation in Go crypto/elliptic, which is | Apr 21, 2023 | 9.1 | 27 | NO | NO |
CVE-2023-26557HIGH io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it relies on Go big.Int, which is not constant time for Cmp, modu | Apr 21, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-47930MEDIUM An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implementation, which makes replaying and spoofi | Apr 21, 2023 | 6.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iofinnet.
Media articles that mention a CVE ID that affects a product developed by Iofinnet — matched by CVE ID, not by vendor name.