VYPR
Medium severity5.5NVD Advisory· Published Aug 23, 2022· Updated Jun 17, 2026

CVE-2021-3798

CVE-2021-3798

Description

A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:opencryptoki_project:opencryptoki:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:opencryptoki_project:opencryptoki:*:*:*:*:*:*:*:*range: <3.17.0
    • (no CPE)
    • (no CPE)range: Fixed in v3.17.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.