VYPR
Medium severity5.3NVD Advisory· Published Nov 12, 2022· Updated Jun 17, 2026

CVE-2022-45195

CVE-2022-45195

Description

SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for the double ratchet protocol.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:simplex:simplex_chat:*:*:*:*:*:*:*:*
    Range: <4.2
  • SimpleX/SimpleXMQ2 versions
    cpe:2.3:a:simplex:simplexmq:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:simplex:simplexmq:*:*:*:*:*:*:*:*range: <3.4.0
    • (no CPE)range: <3.4.0
  • SimpleXMQ/SimpleXMQdescription
  • Range: <4.2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.