Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27825 | Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the ed25519_key structure. |
Wed, 04 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows Wolfssl wolfssl |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:wolfssl:wolfssl:5.6.6:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows Wolfssl wolfssl |
Fri, 30 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wolfssl
Wolfssl wolfcrypt |
|
| CPEs | cpe:2.3:a:wolfssl:wolfcrypt:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wolfssl
Wolfssl wolfcrypt |
|
| Metrics |
ssvc
|
Thu, 29 Aug 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the ed25519_key structure. | |
| Title | Fault Injection of EdDSA signature in WolfCrypt | |
| Weaknesses | CWE-1256 CWE-252 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: wolfSSL
Published:
Updated: 2024-08-30T14:18:36.327Z
Reserved: 2024-03-25T22:01:53.209Z
Link: CVE-2024-2881
Updated: 2024-08-30T14:17:42.876Z
Status : Analyzed
Published: 2024-08-30T00:15:04.917
Modified: 2024-09-04T14:27:24.057
Link: CVE-2024-2881
No data.
OpenCVE Enrichment
No data.
EUVD