CyberRota Analysis
AI-GeneratedThe mirage-crypto-ec package prior to version 2.4.0 for OCaml is vulnerable to a timing side channel attack during NIST elliptic-curve scalar multiplication, where the time taken for a lookup may reveal secret information. This could potentially allow an attacker to exploit the timing variations to recover sensitive cryptographic keys. Organizations using this package should prioritize upgrading to version 2.4.0 or later to mitigate the risk of key exposure.
Original NVD Description
An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.