CVE-2022-44310
24.02.2023, 20:15
In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.Enginsight
Vendor | Product | Version |
---|---|---|
ecdh_project | ecdh | 𝑥 < 0.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration