CVE-2024-22340

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack.
References
Link Resource
https://www.ibm.com/support/pages/node/7185282 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:common_cryptographic_architecture:*:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

25 Jul 2025, 18:12

Type Values Removed Values Added
Summary
  • (es) IBM Common Cryptographic Architecture 7.0.0 a 7.5.51 podría permitir que un atacante remoto obtenga información confidencial durante la creación de firmas ECDSA para realizar un ataque basado en tiempo.
First Time Ibm common Cryptographic Architecture
Ibm aix
Linux
Ibm
Linux linux Kernel
Ibm i
References () https://www.ibm.com/support/pages/node/7185282 - () https://www.ibm.com/support/pages/node/7185282 - Vendor Advisory
CPE cpe:2.3:a:ibm:common_cryptographic_architecture:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*

11 Mar 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 01:15

Updated : 2025-07-25 18:12


NVD link : CVE-2024-22340

Mitre link : CVE-2024-22340

CVE.ORG link : CVE-2024-22340


JSON object : View

Products Affected

ibm

  • common_cryptographic_architecture
  • aix
  • i

linux

  • linux_kernel
CWE
CWE-208

Observable Timing Discrepancy