Use of a Cryptographic Primitive with a Risky Implementation in elliptic - CVE-2025-14505

 

Use of a Cryptographic Primitive with a Risky Implementation in elliptic - CVE-2025-14505

Published: March 6, 2026


Vulnerability identifier: #VU123597
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14505
CWE-ID: CWE-1240
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to secret key.

The vulnerability exists due to ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' has leading zeros and is susceptible to cryptanalysis, which can lead to secret key exposure. A remote attacker can under certain conditions derive the secret key, if they could get their hands on both a faulty signature generated by a vulnerable version of Elliptic and a correct signature for the same inputs


Affected software

elliptic
watsonx Code Assistant On Prem
Storage Scale
Platform Navigator in IBM Cloud Pak for Integration (CP4I)

How to mitigate CVE-2025-14505

Install updates from vendor's website.

watsonx Code Assistant On Prem - update to 5.3.1
Storage Scale - addressed in versions 5.2.3.7, 6.0.0.2
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.21, 16.1.3.2

External References

Related Security Bulletins