CVE-2021-20305

HIGHCVSS 8.1/10EPSS 1.61%

Last modified

CVE-2021-20305 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. EPSS estimates a 1.61% chance of exploitation in the next 30 days.

Description

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.61%

72.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Nettle ProjectNettle< 3.7.2
FedoraprojectFedora33
RedhatEnterprise Linux7.0
RedhatEnterprise Linux8.0
NetappActive Iq Unified ManagerAll versions
NetappOntap Select Deploy Administration UtilityAll versions
DebianDebian Linux9.0
DebianDebian Linux10.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-20305?
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.
How severe is CVE-2021-20305?
CVE-2021-20305 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 1.61% probability of exploitation in the next 30 days.
How do I fix CVE-2021-20305?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-20305?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST