Vulnerability Description
In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ecdh Project | Ecdh | < 0.2.0 |
Related Weaknesses (CWE)
References
- https://github.com/developmentil/ecdh/issues/3ExploitIssue Tracking
- https://github.com/developmentil/ecdh/issues/3ExploitIssue Tracking
FAQ
What is CVE-2022-44310?
CVE-2022-44310 is a vulnerability with a CVSS score of 7.5 (HIGH). In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.
How severe is CVE-2022-44310?
CVE-2022-44310 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-44310?
Check the references section above for vendor advisories and patch information. Affected products include: Ecdh Project Ecdh.