Medium severity5.5NVD Advisory· Published Aug 23, 2022· Updated Jun 17, 2026
CVE-2021-3798
CVE-2021-3798
Description
A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:opencryptoki_project:opencryptoki:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:opencryptoki_project:opencryptoki:*:*:*:*:*:*:*:*range: <3.17.0
- (no CPE)
- (no CPE)range: Fixed in v3.17.0
Patches
Vulnerability mechanics
References
4- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- github.com/opencryptoki/opencryptoki/commit/4e3b43c3d8844402c04a66b55c6c940f965109f0nvdPatchThird Party Advisory
- github.com/opencryptoki/opencryptoki/pull/402nvdPatchThird Party Advisory
- access.redhat.com/security/cve/CVE-2021-3798nvdThird Party Advisory
News mentions
0No linked articles in our index yet.