CVE-2024-45191

Aug. 22, 2024, 9:35 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Matrix libolm (Olm)

  • 3.2.16 and before

Source

cve@mitre.org

Tags

CVE-2024-45191 details

Published : Aug. 22, 2024, 4:15 p.m.
Last Modified : Aug. 22, 2024, 9:35 p.m.

Description

An issue was discovered in Matrix libolm (aka Olm) through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Score

1 2 3 4 5 6 7 8 9.8 10

Weakness

Weakness Name Description
CWE-208 Observable Timing Discrepancy Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

9.8

Exploitability Score

3.9

Impact Score

5.9

Base Severity

CRITICAL

This website uses the NVD API, but is not approved or certified by it.