Lucene search

K
nvd[email protected]NVD:CVE-2023-46324
HistoryOct 23, 2023 - 1:15 a.m.

CVE-2023-46324

2023-10-2301:15:07
CWE-347
web.nvd.nist.gov
4
cve-2023-46324
invalid curve attack
unvalidated public key
sucis
shared secret

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

31.2%

pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker’s public key.

Affected configurations

Nvd
Node
golanggoRange<1.19
AND
free5gcudmRange<1.2.0go
VendorProductVersionCPE
golanggo*cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
free5gcudm*cpe:2.3:a:free5gc:udm:*:*:*:*:*:go:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

31.2%

Related for NVD:CVE-2023-46324