CVE-2023-24025
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/01/2023
Last modified:
02/04/2025
Description
CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via a template side-channel attack because of intermediate data leakage of one vector.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pqclean_project:pqclean:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://csrc.nist.gov/Projects/post-quantum-cryptography/selected-algorithms-2022
- https://eprint.iacr.org/2023/050
- https://github.com/PQClean/PQClean/tree/d03da3053491e767ef842deaef43fc5bdb6bc911
- https://csrc.nist.gov/Projects/post-quantum-cryptography/selected-algorithms-2022
- https://eprint.iacr.org/2023/050
- https://github.com/PQClean/PQClean/tree/d03da3053491e767ef842deaef43fc5bdb6bc911



