Covert Timing Channel
CVE-2024-11862
Summary
Non constant time cryptographic operation in Devolutions.XTS.NET prior to 2024.11.26 allows an attacker to render half of the encryption key obsolete via a timing attack.
- HIGH
- LOCAL
- LOW
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-385 - Covert Timing Channel
Covert timing channels convey information by modulating some aspect of system behavior over time, so that the program receiving the information can observe system behavior and infer protected information.
References
Advisory Timeline
- Published