CVE Vulnerabilities

CVE-2022-24402

Small Space of Random Values

Published: Oct 19, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase, which is insufficient to safeguard against exhaustive search attacks.

Weakness

The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.

Affected Software

Name Vendor Start Version End Version
Tetra:burst Midnightblue - (including) - (including)

Potential Mitigations

References