Tss Lib
Vendor:
First CVE: Dec 23, 2022 · Active for 3 years
4
Total CVEs
More Total CVEs than 72% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tss Lib over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2022
3 years ago
Most Recent CVE
Apr 21, 2023
1,193 days ago
CVE Severity & Scoring
Tss Lib4 CVEs
25%
25%
50%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (75.0%)
High1 (25.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (25.0%)
High0 (0.0%)
None3 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47931CRITICAL IO FinNet tss-lib before 2.0.0 allows a collision of hash values. | Dec 23, 2022 | 9.1 | 28 | NO | NO |
CVE-2023-26556CRITICAL io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implementation in Go crypto/elliptic, which is | Apr 21, 2023 | 9.1 | 27 | NO | NO |
CVE-2023-26557HIGH io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it relies on Go big.Int, which is not constant time for Cmp, modu | Apr 21, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-47930MEDIUM An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implementation, which makes replaying and spoofi | Apr 21, 2023 | 6.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Tss Lib
Top CWEs
Versions
No cataloged versions.