CVE & CISA-KEV Catalog

CVE-2024-13176

MEDIUM
4.1
CVSS v3
NVD

Description

Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network connection with low latency. For that reason the severity of this vulnerability is Low. The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.

How to fix

Remediation Available
edk2Debian
Fixed in:2025.02-8+deb13u1CVE-2024-13176
Fixed in:2025.02-9CVE-2024-13176
edk2Ubuntu
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
libssl1.1Ubuntu
Fixed in:1.1.1f-1ubuntu2.24USN-7278-1
libssl3Ubuntu
Fixed in:3.0.2-0ubuntu1.19USN-7278-1
libssl3t64Ubuntu
Fixed in:3.0.13-0ubuntu3.5USN-7278-1
opensslUbuntu
Fixed in:1.1.1f-1ubuntu2.24USN-7278-1
Fixed in:3.0.2-0ubuntu1.19USN-7278-1
Fixed in:3.0.13-0ubuntu3.5USN-7278-1
ovmfUbuntu
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
ovmf-ia32Ubuntu
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
qemu-efiUbuntu
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
qemu-efi-aarch64Ubuntu
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
qemu-efi-armUbuntu
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
qemu-efi-riscv64Ubuntu
Fixed in:2024.02-2ubuntu0.6USN-7894-1

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorPhysical
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityLow
IntegrityLow
AvailabilityLow

CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Exploit Intelligence

0.60%probability of exploitation in 30 days
44thpercentile

Moderate risk: more likely to be exploited than 44% of all known CVEs.

References

Embed a live status badge for CVE-2024-13176
CVE-2024-13176 severity badge

Markdown

[![CVE-2024-13176](https://tridentstack.com/cve/badge/CVE-2024-13176.svg)](https://tridentstack.com/cve/CVE-2024-13176)

HTML

<a href="https://tridentstack.com/cve/CVE-2024-13176"><img src="https://tridentstack.com/cve/badge/CVE-2024-13176.svg" alt="CVE-2024-13176"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-11-03.