Vulnerabilities > CVE-2019-20399 - Information Exposure Through Discrepancy vulnerability in Parity Libsecp256K1

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
parity
CWE-203

Summary

A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak information via a side-channel attack.

Common Weakness Enumeration (CWE)