CVE-2024-22340: IBM Common Cryptographic Architecture information disclosure
IBM CCA could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack.
Other sources
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51
could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22340?
CVE-2024-22340 is classified as a medium severity vulnerability due to its potential to allow remote attackers to exploit timing-based attacks.
How do I fix CVE-2024-22340?
To fix CVE-2024-22340, upgrade to IBM Common Cryptographic Architecture version 7.5.52 or later.
Which versions are affected by CVE-2024-22340?
CVE-2024-22340 affects IBM Common Cryptographic Architecture versions from 7.0.0 to 7.5.51.
What type of information can be leaked due to CVE-2024-22340?
CVE-2024-22340 may allow attackers to obtain sensitive information related to ECDSA signature creation.
Is CVE-2024-22340 a local or remote vulnerability?
CVE-2024-22340 is a remote vulnerability that can be exploited by attackers over the network.