CVE-2022-23004
Published on: Not Yet Published
Last Modified on: 08/05/2022 06:49:00 PM UTC
Certain versions of Sweet B from Westerndigital contain the following vulnerability:
When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned from the library, and an invalid unreduced value is written to the output buffer. This may be leveraged by an attacker to cause an error scenario, resulting in a limited denial of service for an individual user. The scope of impact cannot extend to other components.
- CVE-2022-23004 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Western Digital - Sweet B Library version < v2
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | LOW |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
WDC-22013 Sweet B Incorrect Output Vulnerabilities | Western Digital | www.westerndigital.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Westerndigital | Sweet B | 1 | All | All | All |
- cpe:2.3:a:westerndigital:sweet_b:1:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-23004 : When computing a shared secret or point multiplication on the NIST P-256 curve using a public key… twitter.com/i/web/status/1… | 2022-07-29 19:04:11 |
![]() |
CVE-2022-23004 | 2022-07-29 20:38:24 |