CVE-2024-11862: Devolutions Xts.net

Medium severity, CVSS 5.1. EPSS: 0.1% chance of exploitation in the next 30 days.

Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks

Affected products

  • Devolutions Xts.net: before 2024.11.26 (fixed in 2024.11.26)

Published 2024-11-27. Last modified 2026-06-17.