CWE-1279: Cryptographic Operations are run Before Supporting Units are Ready
Performing cryptographic operations without ensuring that the supporting inputs are ready to supply valid data may compromise the cryptographic result.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-22473 — Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices
- CVE-2025-29779 — Post-Quantum Secure Feldman's Verifiable Secret Sharing has Inadequate Fault Injection Countermeasures in `secure_redundant_execution`
Recently published
- CVE-2025-29779 — Post-Quantum Secure Feldman's Verifiable Secret Sharing has Inadequate Fault Injection Countermeasures in `secure_redundant_execution`
- CVE-2024-22473 — Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices