Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3394 | Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks |
Github GHSA |
GHSA-j6vm-4r7g-x4gr | Devolutions.XTS.NET Vulnerable to Timing Attack on GF Multiplications |
Wed, 27 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 Nov 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks | |
| Weaknesses | CWE-385 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2024-11-27T14:53:57.448Z
Reserved: 2024-11-27T14:20:27.011Z
Link: CVE-2024-11862
Updated: 2024-11-27T14:53:53.623Z
Status : Deferred
Published: 2024-11-27T15:15:25.393
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-11862
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA