cbcvebase.
CVE-2024-13176
published 2025-01-20

CVE-2024-13176: Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A…

PriorityP418medium4.1CVSS 3.1
AVPACLPRLUINSUCLILAL
EPSS
0.60%
44.8th percentile
Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network connection with low latency. For that reason the severity of this vulnerability is Low. The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianedk2< edk2 2025.02-9 (forky)edk2 2025.02-9 (forky)
debianopenssl< edk2 2025.02-9 (forky)edk2 2025.02-9 (forky)
opensslopenssl>= 0 < 3.0.19-r03.0.19-r0
opensslopenssl>= 0 < 3.1.8-r03.1.8-r0
opensslopenssl>= 0 < 3.1.8-r03.1.8-r0
opensslopenssl>= 0 < 3.3.2-r23.3.2-r2
opensslopenssl>= 0 < 3.3.2-r53.3.2-r5
opensslopenssl>= 0 < 3.3.2-r53.3.2-r5
opensslopenssl>= 0 < 3.3.2-r53.3.2-r5
opensslopenssl>= 0 < 1.1.1w-0+deb11u31.1.1w-0+deb11u3
opensslopenssl>= 0 < 3.0.16-1~deb12u13.0.16-1~deb12u1
opensslopenssl>= 0 < 3.4.1-13.4.1-1
opensslopenssl>= 0 < 3.4.1-13.4.1-1
opensslopenssl>= 0 < 1.1.1f-1ubuntu2.241.1.1f-1ubuntu2.24
opensslopenssl>= 0 < 3.0.2-0ubuntu1.193.0.2-0ubuntu1.19
opensslopenssl>= 0 < 3.0.13-0ubuntu3.53.0.13-0ubuntu3.5
opensslopenssl>= 0 < 3.3.1-2ubuntu2.13.3.1-2ubuntu2.1
opensslopenssl>= 1.0.2 < 1.0.2zl1.0.2zl
opensslopenssl>= 1.1.1 < 1.1.1zb1.1.1zb
opensslopenssl>= 3.0.0 < 3.0.163.0.16
opensslopenssl>= 3.1.0 < 3.1.83.1.8
opensslopenssl>= 3.2.0 < 3.2.43.2.4
opensslopenssl>= 3.3.0 < 3.3.33.3.3
opensslopenssl>= 3.4.0 < 3.4.13.4.1
tianocoreedk2>= 0 < 2025.02-8+deb13u12025.02-8+deb13u1

CVSS provenance

nvdv3.14.1MEDIUMCVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv7.4HIGH
vendor_ubuntu7.4HIGH
vendor_oracle4.3MEDIUM
vendor_debian4.1MEDIUM
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.