CVE-2007-6755
published 2013-10-11CVE-2007-6755: The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a…
PriorityP423medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.41%
69.7th percentile
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 1.1.0b-2 (bookworm) | openssl 1.1.0b-2 (bookworm) |
| dell | bsafe_crypto-c-micro-edition | 3.0.0.0 – 3.0.0.20 | — |
| dell | bsafe_crypto-j | — | — |
| dell | bsafe_crypto-j | — | — |
| emc | rsa_data_protection_manager | — | — |
| openssl | openssl | >= 0 < 1.1.0b-2 | 1.1.0b-2 |
| openssl | openssl | >= 0 < 1.1.0b-2 | 1.1.0b-2 |
| openssl | openssl | >= 0 < 1.1.0b-2 | 1.1.0b-2 |
| openssl | openssl | >= 0 < 1.1.0b-2 | 1.1.0b-2 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-whq3-8f4v-48fj: The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random B
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-6078 [MEDIUM] GHSA-whq3-8f4v-48fj: The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random B
The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging unspecified "security concerns," aka the ESA-2013-068 issue. NOTE: this issue has been SPLIT from CVE-2007-6755 because the vendor announcement did not state a specific technical rationale for a change in the algorithm; thus, CVE cannot reach a conclusion that a CVE-2007-6755 concern was the reason, or one of the reasons, for this change.
GHSA
GHSA-32vp-w632-vwm4: The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only
ghsa_unreviewed·2022-05-13·CVSS 5.8
CVE-2014-4192 [MEDIUM] GHSA-32vp-w632-vwm4: The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only
The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only the requested byte count and not the use of cached bytes, which makes it easier for remote attackers to obtain plaintext from TLS sessions by recovering the algorithm's inner state, a different issue than CVE-2007-6755.
GHSA
GHSA-q2w9-mwc3-mq6f: The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) sends a long series of random bytes during use of the Dual_EC_DRBG algori
ghsa_unreviewed·2022-05-13·CVSS 5.8
CVE-2014-4191 [MEDIUM] GHSA-q2w9-mwc3-mq6f: The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) sends a long series of random bytes during use of the Dual_EC_DRBG algori
The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) sends a long series of random bytes during use of the Dual_EC_DRBG algorithm, which makes it easier for remote attackers to obtain plaintext from TLS sessions by recovering the algorithm's inner state, a different issue than CVE-2007-6755.
GHSA
GHSA-cg5m-695g-74cp: The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algor
ghsa_unreviewed·2022-05-13·CVSS 5.8
CVE-2014-4193 [MEDIUM] GHSA-cg5m-695g-74cp: The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algor
The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algorithm, which makes it easier for remote attackers to obtain plaintext from TLS sessions by requesting long nonces from a server, a different issue than CVE-2007-6755.
GHSA
GHSA-3mqf-x495-xqrw: The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constan
ghsa_unreviewed·2022-05-01
CVE-2007-6755 [MEDIUM] CWE-327 GHSA-3mqf-x495-xqrw: The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constan
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.
OSV
CVE-2007-6755: The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constan
osv·2013-10-11·CVSS 5.8
CVE-2007-6755 [MEDIUM] CVE-2007-6755: The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constan
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.
Red Hat
Dual_EC_DRBG: weak pseudo random number generator
vendor_redhat·2013-10-11·CVSS 5.8
CVE-2007-6755 [MEDIUM] Dual_EC_DRBG: weak pseudo random number generator
Dual_EC_DRBG: weak pseudo random number generator
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.
Statement: Not vulnerable. This issue did not affect cryptography library packages as shipped with Red Hat products, as they do not implement Dual EC DRBG algorithm.
Package: gnutls (Red Hat Enterprise
Debian
CVE-2007-6755: openssl - The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic R...
vendor_debian·2007·CVSS 5.8
CVE-2007-6755 [MEDIUM] CVE-2007-6755: openssl - The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic R...
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.
Scope: local
bookworm: resolved (fixed in 1.1.0b-2)
bullseye: resolved (fixed in 1.1.0b-2)
forky: resolved (fixed in 1.1.0b-2)
sid: resolved (fixed in 1.1.0b-2)
trixie: resolved (fixed in 1.1.0b-2)
No detection rules found.
No public exploits indexed.
http://arstechnica.com/security/2013/09/stop-using-nsa-influence-code-in-our-product-rsa-tells-customers/http://blog.cryptographyengineering.com/2013/09/rsa-warns-developers-against-its-own.htmlhttp://blog.cryptographyengineering.com/2013/09/the-many-flaws-of-dualecdrbg.htmlhttp://rump2007.cr.yp.to/15-shumow.pdfhttp://stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2-332655/http://threatpost.com/in-wake-of-latest-crypto-revelations-everything-is-suspecthttp://www.securityfocus.com/bid/63657https://www.schneier.com/blog/archives/2007/11/the_strange_sto.htmlhttp://arstechnica.com/security/2013/09/stop-using-nsa-influence-code-in-our-product-rsa-tells-customers/http://blog.cryptographyengineering.com/2013/09/rsa-warns-developers-against-its-own.htmlhttp://blog.cryptographyengineering.com/2013/09/the-many-flaws-of-dualecdrbg.htmlhttp://rump2007.cr.yp.to/15-shumow.pdfhttp://stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2-332655/http://threatpost.com/in-wake-of-latest-crypto-revelations-everything-is-suspecthttp://www.securityfocus.com/bid/63657https://www.schneier.com/blog/archives/2007/11/the_strange_sto.html
2013-10-11
Published