CVE-2011-1945

Description

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
4.848

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in OpenSSL 1.0.0dWindows
Vulnerabilities CVE-2006-7250,CVE-2009-2409,CVE-2011-1945,CVE-2012-1165 are affected in OpenSSL 0.9.8kWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.1cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.2bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.3Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.3aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.4Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.5Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.5aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6gWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6hWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6iWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6jWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6kWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6lWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6mWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7gWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7hWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7iWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7jWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7kWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7lWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7mWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8gWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234