Improper random reading in CIRCL
CVE-2023-1732

5.3MEDIUM

Key Information:

Vendor

Cloudflare

Status
Vendor
CVE Published:
10 May 2023

What is CVE-2023-1732?

The implementation of cryptographic components Kyber and FrodoKEM in Cloudflare products contains a flaw in randomness sampling for shared secrets. A failure to verify whether the crypto/rand.Read() function returns an error can lead to scenarios where predictable shared secrets are generated, particularly under rare deployment circumstances. Additionally, components like tkn20 and blindrsa fail to adequately check if sufficient randomness is provided by user-supplied sources. This oversight may compromise the integrity of the plaintext, as weakened blinding in blindrsa no longer assures robust security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CIRCL Go 0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tom Thorogood
.