Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2007-6755 Details

Description

The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://arstechnica.com/security/2013/09/stop-using-nsa-influence-code-in-our-product-rsa-tells-customers/ CVEThird Party Advisory
http://blog.cryptographyengineering.com/2013/09/rsa-warns-developers-against-its-own.html CVEThird Party Advisory
http://blog.cryptographyengineering.com/2013/09/the-many-flaws-of-dualecdrbg.html CVEThird Party Advisory
http://rump2007.cr.yp.to/15-shumow.pdf CVEThird Party Advisory
http://stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2-332655/ CVENot Applicable

see all 16 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-327Use of a Broken or Risky Cryptographic Algorithm[email protected]

Affected Products

ProductVersions
dell bsafe crypto-c-micro-edition
>= 3.0.0.0, <= 3.0.0.20

CPE

  • cpe:2.3:a:dell:bsafe_crypto-c-micro-edition:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
dell bsafe crypto-j
5.0
5.0.1

CPE

  • cpe:2.3:a:dell:bsafe_crypto-j:5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:dell:bsafe_crypto-j:5.0.1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

9 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2007-6755
NVD Published Date:
Oct 11, 2013
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2007-6755 Details - Not Deferred