CVE-2007-6755
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.
Published:Oct 11, 2013
Last Modified:Apr 11, 2025
EPS:Oct 11, 2013
EPSS Score:0.00516
CVSS Score:5.8
Affected Products
Vendor
Product
Action
Vendor
Dell
Product
Bsafe Crypto-c-micro-edition
Dell
Bsafe Crypto-c-micro-edition
Vendor
Dell
Product
Bsafe Crypto-j
Dell
Bsafe Crypto-j
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
