CVE-2024-13176
published 2025-01-20CVE-2024-13176: Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A…
PriorityP418medium4.1CVSS 3.1
AVPACLPRLUINSUCLILAL
EPSS
0.60%
44.8th percentile
Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation.
Impact summary: A timing side-channel in ECDSA signature computations
could allow recovering the private key by an attacker. However, measuring
the timing would require either local access to the signing application or
a very fast network connection with low latency.
There is a timing signal of around 300 nanoseconds when the top word of
the inverted ECDSA nonce value is zero. This can happen with significant
probability only for some of the supported elliptic curves. In particular
the NIST P-521 curve is affected. To be able to measure this leak, the attacker
process must either be located in the same physical computer or must
have a very fast network connection with low latency. For that reason
the severity of this vulnerability is Low.
The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | edk2 | < edk2 2025.02-9 (forky) | edk2 2025.02-9 (forky) |
| debian | openssl | < edk2 2025.02-9 (forky) | edk2 2025.02-9 (forky) |
| openssl | openssl | >= 0 < 3.0.19-r0 | 3.0.19-r0 |
| openssl | openssl | >= 0 < 3.1.8-r0 | 3.1.8-r0 |
| openssl | openssl | >= 0 < 3.1.8-r0 | 3.1.8-r0 |
| openssl | openssl | >= 0 < 3.3.2-r2 | 3.3.2-r2 |
| openssl | openssl | >= 0 < 3.3.2-r5 | 3.3.2-r5 |
| openssl | openssl | >= 0 < 3.3.2-r5 | 3.3.2-r5 |
| openssl | openssl | >= 0 < 3.3.2-r5 | 3.3.2-r5 |
| openssl | openssl | >= 0 < 1.1.1w-0+deb11u3 | 1.1.1w-0+deb11u3 |
| openssl | openssl | >= 0 < 3.0.16-1~deb12u1 | 3.0.16-1~deb12u1 |
| openssl | openssl | >= 0 < 3.4.1-1 | 3.4.1-1 |
| openssl | openssl | >= 0 < 3.4.1-1 | 3.4.1-1 |
| openssl | openssl | >= 0 < 1.1.1f-1ubuntu2.24 | 1.1.1f-1ubuntu2.24 |
| openssl | openssl | >= 0 < 3.0.2-0ubuntu1.19 | 3.0.2-0ubuntu1.19 |
| openssl | openssl | >= 0 < 3.0.13-0ubuntu3.5 | 3.0.13-0ubuntu3.5 |
| openssl | openssl | >= 0 < 3.3.1-2ubuntu2.1 | 3.3.1-2ubuntu2.1 |
| openssl | openssl | >= 1.0.2 < 1.0.2zl | 1.0.2zl |
| openssl | openssl | >= 1.1.1 < 1.1.1zb | 1.1.1zb |
| openssl | openssl | >= 3.0.0 < 3.0.16 | 3.0.16 |
| openssl | openssl | >= 3.1.0 < 3.1.8 | 3.1.8 |
| openssl | openssl | >= 3.2.0 < 3.2.4 | 3.2.4 |
| openssl | openssl | >= 3.3.0 < 3.3.3 | 3.3.3 |
| openssl | openssl | >= 3.4.0 < 3.4.1 | 3.4.1 |
| tianocore | edk2 | >= 0 < 2025.02-8+deb13u1 | 2025.02-8+deb13u1 |
CVSS provenance
nvdv3.14.1MEDIUMCVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv7.4HIGH
vendor_ubuntu7.4HIGH
vendor_oracle4.3MEDIUM
vendor_debian4.1MEDIUM
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
EDK II regression
vendor_ubuntu·2025-11-28·CVSS 5.8
CVE-2023-45236 [MEDIUM] EDK II regression
Title: EDK II regression
Summary: USN-7894-1 introduced a regression in EDK II
USN-7894-1 fixed vulnerabilities in EDK II. The update introduced a
regression in the UEFI network boot. This update reverts the corresponding
fixes for CVE-2023-45236 and CVE-2023-45237 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS
Ubuntu
EDK II vulnerabilities
vendor_ubuntu·2025-11-26·CVSS 7.4
CVE-2023-45236 [HIGH] EDK II vulnerabilities
Title: EDK II vulnerabilities
Summary: Several security issues were fixed in EDK II.
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-1298)
It was discovered that the EDK II PE/COFF loader incorrectly handled
certain memory operations. An attacker could possibly use this issue to
cause a denial of service, obtain sensitive information, or execute
arbitrary code. This issue o
Oracle
Oracle Oracle JD Edwards Risk Matrix: World Software Security (OpenSSL) — CVE-2024-13176
vendor_oracle·2025-07-15·CVSS 4.1
CVE-2024-13176 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: World Software Security (OpenSSL) — CVE-2024-13176
Oracle Oracle JD Edwards Risk Matrix: World Software Security (OpenSSL) vulnerability
CVE: CVE-2024-13176
CVSS: 4.1
Protocol: None
Remote exploit: No
Affected versions: Physical
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Database (OpenSSL) — CVE-2024-13176
vendor_oracle·2025-04-15·CVSS 4.3
CVE-2024-13176 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Database (OpenSSL) — CVE-2024-13176
Oracle Oracle Database Server Risk Matrix: Oracle Database (OpenSSL) vulnerability
CVE: CVE-2024-13176
CVSS: 4.3
Protocol: None
Remote exploit: No
Affected versions: Physical
Advisory: cpuapr2025 (APR 2025)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2025-02-20·CVSS 4.1
CVE-2024-13176 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
George Pantelakis and Alicja Kario discovered that OpenSSL had a timing
side-channel when performing ECDSA signature computations. A remote
attacker could possibly use this issue to recover private data.
(CVE-2024-13176)
It was discovered that OpenSSL incorrectly handled certain memory
operations when using low-level GF(2^m) elliptic curve APIs with untrusted
explicit values for the field polynomial. When being used in this uncommon
fashion, a remote attacker could use this issue to cause OpenSSL to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-9143)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2025-02-11·CVSS 6.3
CVE-2024-12797 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
It was discovered that OpenSSL clients incorrectly handled authenticating
servers using RFC7250 Raw Public Keys. In certain cases, the connection
will not abort as expected, possibly causing the communication to be
intercepted. (CVE-2024-12797)
George Pantelakis and Alicja Kario discovered that OpenSSL had a timing
side-channel when performing ECDSA signature computations. A remote
attacker could possibly use this issue to recover private data.
(CVE-2024-13176)
It was discovered that OpenSSL incorrectly handled certain memory
operations when using low-level GF(2^m) elliptic curve APIs with untrusted
explicit values for the field polynomial. When being used in this uncommon
fashion, a remote attacker
Red Hat
openssl: Timing side-channel in ECDSA signature computation
vendor_redhat·2025-01-20·CVSS 4.1
CVE-2024-13176 [MEDIUM] CWE-385 openssl: Timing side-channel in ECDSA signature computation
openssl: Timing side-channel in ECDSA signature computation
Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation.
Impact summary: A timing side-channel in ECDSA signature computations
could allow recovering the private key by an attacker. However, measuring
the timing would require either local access to the signing application or
a very fast network connection with low latency.
There is a timing signal of around 300 nanoseconds when the top word of
the inverted ECDSA nonce value is zero. This can happen with significant
probability only for some of the supported elliptic curves. In particular
the NIST P-521 curve is affected. To be able to measure this leak, the attacker
process must either be located in t
Debian
CVE-2024-13176: edk2 - Issue summary: A timing side-channel which could potentially allow recovering th...
vendor_debian·2024·CVSS 4.1
CVE-2024-13176 [MEDIUM] CVE-2024-13176: edk2 - Issue summary: A timing side-channel which could potentially allow recovering th...
Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network co
OSV
edk2 regression
osv·2025-11-28·CVSS 7.4
CVE-2023-45236 [HIGH] edk2 regression
edk2 regression
USN-7894-1 fixed vulnerabilities in EDK II. The update introduced a
regression in the UEFI network boot. This update reverts the corresponding
fixes for CVE-2023-45236 and CVE-2023-45237 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-1298)
It was discovered that
OSV
edk2 vulnerabilities
osv·2025-11-26·CVSS 7.4
CVE-2023-45236 [HIGH] edk2 vulnerabilities
edk2 vulnerabilities
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-1298)
It was discovered that the EDK II PE/COFF loader incorrectly handled
certain memory operations. An attacker could possibly use this issue to
cause a denial of service, obtain sensitive information, or execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2024-38
OSV
openssl vulnerabilities
osv·2025-02-20·CVSS 4.1
CVE-2024-13176 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
George Pantelakis and Alicja Kario discovered that OpenSSL had a timing
side-channel when performing ECDSA signature computations. A remote
attacker could possibly use this issue to recover private data.
(CVE-2024-13176)
It was discovered that OpenSSL incorrectly handled certain memory
operations when using low-level GF(2^m) elliptic curve APIs with untrusted
explicit values for the field polynomial. When being used in this uncommon
fashion, a remote attacker could use this issue to cause OpenSSL to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-9143)
OSV
openssl vulnerabilities
osv·2025-02-11·CVSS 6.3
CVE-2024-12797 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
It was discovered that OpenSSL clients incorrectly handled authenticating
servers using RFC7250 Raw Public Keys. In certain cases, the connection
will not abort as expected, possibly causing the communication to be
intercepted. (CVE-2024-12797)
George Pantelakis and Alicja Kario discovered that OpenSSL had a timing
side-channel when performing ECDSA signature computations. A remote
attacker could possibly use this issue to recover private data.
(CVE-2024-13176)
It was discovered that OpenSSL incorrectly handled certain memory
operations when using low-level GF(2^m) elliptic curve APIs with untrusted
explicit values for the field polynomial. When being used in this uncommon
fashion, a remote attacker could use this issue to cause OpenSSL to crash,
resulting in a d
GHSA
GHSA-r9fv-h47r-823f: Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation
ghsa_unreviewed·2025-01-20
CVE-2024-13176 [MEDIUM] CWE-385 GHSA-r9fv-h47r-823f: Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation
Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation.
Impact summary: A timing side-channel in ECDSA signature computations
could allow recovering the private key by an attacker. However, measuring
the timing would require either local access to the signing application or
a very fast network connection with low latency.
There is a timing signal of around 300 nanoseconds when the top word of
the inverted ECDSA nonce value is zero. This can happen with significant
probability only for some of the supported elliptic curves. In particular
the NIST P-521 curve is affected. To be able to measure this leak, the attacker
process must either be located in the same physical computer or must
have a very fast network
OSV
CVE-2024-13176: Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation
osv·2025-01-20·CVSS 4.1
CVE-2024-13176 [MEDIUM] CVE-2024-13176: Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation
Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network co
OSV
CVE-2024-13176: Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation
osv·2025-01-20·CVSS 4.1
CVE-2024-13176 [MEDIUM] CVE-2024-13176: Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation
Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation.
Impact summary: A timing side-channel in ECDSA signature computations
could allow recovering the private key by an attacker. However, measuring
the timing would require either local access to the signing application or
a very fast network connection with low latency.
There is a timing signal of around 300 nanoseconds when the top word of
the inverted ECDSA nonce value is zero. This can happen with significant
probability only for some of the supported elliptic curves. In particular
the NIST P-521 curve is affected. To be able to measure this leak, the attacker
process must either be located in the same physical computer or must
have a very fast network
No detection rules found.
No public exploits indexed.
https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916fhttps://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54dedhttps://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86https://openssl-library.org/news/secadv/20250120.txthttp://www.openwall.com/lists/oss-security/2025/01/20/2https://lists.debian.org/debian-lts-announce/2025/05/msg00028.htmlhttps://security.netapp.com/advisory/ntap-20250124-0005/https://security.netapp.com/advisory/ntap-20250418-0010/https://security.netapp.com/advisory/ntap-20250502-0006/
2025-01-20
Published