CVE-2024-28285

CRITICAL

A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose...

Affects 0 products across 2 vendors.

BCS6.76
CVSS 3.19.8
EPSS0.5%
Percentile41th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-209: CWE-209
CWE-285: CWE-285
Related Attack Patterns (CAPEC)
CAPEC-5 Blue Boxing
via CWE-285
CAPEC-7 Blind SQL Injection
via CWE-209
CAPEC-13 Subverting Environment Variable Values
via CWE-285
CAPEC-45 Buffer Overflow via Symbolic Links
via CWE-285
CAPEC-51 Poison Web Service Registry
via CWE-285
Show all 21

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Crypto++ 8.9 allows an attacker to disclose information and escalate privileges by co-residing in the same system with a victim process.

BSID: BS-2024-GLOBAL-206407-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-28285?
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Crypto++ 8.9 allows an attacker to disclose information and escalate privileges by co-residing in the same system with a victim process.
What is the CVSS score for CVE-2024-28285?
CVE-2024-28285 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.5%.
Is CVE-2024-28285 actively exploited?
No confirmed active exploitation of CVE-2024-28285 as of 2026-05-30.
How do I remediate CVE-2024-28285?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-28285?
CVE-2024-28285 affects: Crypto, Cryptopp.
Vulnerability Details
CVE IDCVE-2024-28285
BSIDBS-2024-GLOBAL-206407-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2024-05-14
Last Modified2026-04-15
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited through fault injection techniques, where an attacker can manipulate the execution environment to cause errors in the cryptographic operations, leading to information leakage and privilege escalation.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Crypto —
Cryptopp —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 842 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashe4a6936bce2c261aab67df9f186c0f9ca9eb394cb0a335edf41d16fd116874813f4ce6b2a652352b3515d4f55563245fa6c85a81bbf957f69f1143a840b1628c
Related CVEs affecting Crypto
CVE-2024-32962 10.0 xml-crypto is an xml digital signature and encryption library for Node.js. In... CVE-2026-43493 9.8 In the Linux kernel, the following vulnerability has been resolved: crypto: ... CVE-2025-68726 9.8 In the Linux kernel, the following vulnerability has been resolved: crypto: ... CVE-2024-31695 9.8 A misconfiguration in the fingerprint authentication mechanism of Binance: BT... CVE-2025-48141 9.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje...
View all Crypto CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →