CVE-2022-44310

7.5HIGH

In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.

发布于: 2/24/2023更新于: 3/12/2025

描述

In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.

AI分析AI驱动

受影响产品

ecdh_projectecdh

参考资料