CVE-2022-23004 - CVE House
Back to Database
Status published Medium CVE-2022-23004

Algorithm incorrectly returning error and Invalid unreduced value written to output buffer

Vulnerability Description

When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned from the library, and an invalid unreduced value is written to the output buffer. This may be leveraged by an attacker to cause an error scenario, resulting in a limited denial of service for an individual user. The scope of impact cannot extend to other components.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23004

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Western Digital

View all reports →

Affected Software

Sweet B Library
Vulnerable Versions:
Sweet B Library

Timeline

Official Publish: July 29th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)