« Volver al listado

CVE-2023-24532

Estado: ModificadaMedia (5.3)—

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-24532",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-24532",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-01T15:58:31.679478Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "Go standard library",
          "product": "crypto/internal/nistec",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.19.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.20.0-0",
              "lessThan": "1.20.2",
              "versionType": "semver"
            }
          ],
          "packageName": "crypto/internal/nistec",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "P256Point.ScalarBaseMult"
            },
            {
              "name": "P256Point.ScalarMult"
            },
            {
              "name": "P256OrdInverse"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-03-08T20:15:09.413",
  "references": [
    {
      "url": "https://go.dev/cl/471255",
      "tags": [
        "Patch"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/issue/58647",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/3-TpUx48iQY",
      "tags": [
        "Mailing List",
        "Release Notes"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2023-1621",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/cl/471255",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://go.dev/issue/58647",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/3-TpUx48iQY",
      "tags": [
        "Mailing List",
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2023-1621",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20230331-0011/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-682"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh."
    }
  ],
  "lastModified": "2026-06-17T05:39:28.600",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15520F70-C473-425F-8B9F-FAD4804D32E8",
              "versionEndExcluding": "1.19.7"
            },
            {
              "criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFE15B38-D5B0-4231-BB31-228BAF815F72",
              "versionEndExcluding": "1.20.2",
              "versionStartIncluding": "1.20.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@golang.org"
}