CVE-2015-7940

UnknownEPSS 4.82%

Last modified

CVE-2015-7940 is a vulnerability of currently unknown severity. The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack.". EPSS estimates a 4.82% chance of exploitation in the next 30 days.

Description

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."

Metrics

EPSS Probability
4.82%

90.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OpensuseLeap42.1
OpensuseOpensuse13.1
OpensuseOpensuse13.2
BouncycastleBouncy Castle Crypto Package<= 1.50
OracleApplication Testing Suite12.5.0.1
OracleApplication Testing Suite12.5.0.2
OracleApplication Testing Suite12.5.0.3
OracleEnterprise Manager Ops Center12.1.4
OracleEnterprise Manager Ops Center12.2.2
OraclePeoplesoft Enterprise Peopletools8.54
OraclePeoplesoft Enterprise Peopletools8.55
OracleVirtual Desktop Infrastructure3.5.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-7940?
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
How severe is CVE-2015-7940?
Severity scoring for CVE-2015-7940 is pending analysis. The EPSS model estimates a 4.82% probability of exploitation in the next 30 days.
How do I fix CVE-2015-7940?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-7940?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST