Vulnerability in openCryptoki Allows Extraction of Private Keys via Invalid Curve Attack
CVE-2021-3798
5.5MEDIUM
What is CVE-2021-3798?
A flaw exists in openCryptoki related to the management of EC keys. Specifically, the soft token fails to validate whether an EC key is legitimate during creation (C_CreateObject) and while deriving keys using ECDH public data (C_DeriveKey). This oversight allows an attacker to exploit the system by conducting an invalid curve attack, potentially leading to the unauthorized extraction of private keys, which can compromise the security and integrity of cryptographic operations.
Affected Version(s)
opencryptoki Fixed in v3.17.0
