← volver
CVE-2023-49292mediumCWE-200

Possible private key restoration in go package github.com/ecies/go

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 4.9epss 0.3%
probabilidad de explotación
0.3%top 73% de las CVE
explotación observada
noninguna fuente lo reporta
ecies is an Elliptic Curve Integrated Encryption Scheme for secp256k1 in Golang. If funcations Encapsulate(), Decapsulate() and ECDH() could be called by an attacker, they could recover any private key that interacts with it. This vulnerability was patched in 2.0.8. Users are advised to upgrade.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Productos afectados
ecies · go