CVE-2024-41760
CVSS 3.1 Score 3.7 of 10 (low)
Details
Summary
CVE-2024-41760 is a newly disclosed vulnerability affecting IBM Common Cryptographic Architecture versions 7.0.0 to 7.5.51. An attacker can exploit this timing attack vulnerability during specific RSA operations, potentially gaining unauthorized access to sensitive information. The flaw stems from the cryptographic library's inability to adequately protect against timing differences in processing, making it lucrative for attackers seeking valuable data. IBM has released patches to address this issue, urging users to apply the updates promptly to mitigate potential risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM