Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-20950


Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.


Published

2021-01-19T13:15:11.887

Last Modified

2024-11-21T05:12:20.087

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-327

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ietf public_key_cryptography_standards_\#1 1.5 Yes
Application microchip microchip_libraries_for_applications ≤ 2018-11-26 Yes
Operating System apple macos - No
Operating System linux linux_kernel - No
Operating System microsoft windows - No

References