|
nCipher Insecure Diffie-Hellman Key Generation Vulnerability
Certain nCipher products are susceptible to an insecure Diffie-Hellman (DH) key-generation weakness. This issue is due to the software using random parameters with undesirable properties. This issue results in the creation of cryptographic keys that may have properties that allow attackers to recover the private key in significantly less time than with brute-force. By gaining access to private keys, attackers may gain access to potentially sensitive information, perform man-in-the-middle attacks, or bypass security restrictions that depend on the security properties of the compromised DH keys. Other attacks may also be possible. |
|
|
Privacy Statement |