First published: Mon Mar 10 2025(Updated: )
IBM CCA could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Common Cryptographic Architecture (CCA) | >=7.0.0<=7.5.51 | |
IBM Common Cryptographic Architecture (CCA) 7.x | <=7.0.0 - 7.5.51 | |
IBM 4769 Developers Toolkit | <=7.0.0 - 7.5.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22340 is classified as a medium severity vulnerability due to its potential to allow remote attackers to exploit timing-based attacks.
To fix CVE-2024-22340, upgrade to IBM Common Cryptographic Architecture version 7.5.52 or later.
CVE-2024-22340 affects IBM Common Cryptographic Architecture versions from 7.0.0 to 7.5.51.
CVE-2024-22340 may allow attackers to obtain sensitive information related to ECDSA signature creation.
CVE-2024-22340 is a remote vulnerability that can be exploited by attackers over the network.