CVE-2024-11862: Devolutions Xts.net
Medium severity, CVSS 5.1. EPSS: 0.1% chance of exploitation in the next 30 days.
Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks
Affected products
- Devolutions Xts.net: before 2024.11.26 (fixed in 2024.11.26)
Published 2024-11-27. Last modified 2026-06-17.