4

CVE-2013-1624

The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Data is provided by the National Vulnerability Database (NVD)
BouncycastleBc-java Version1.01
BouncycastleBc-java Version1.02
BouncycastleBc-java Version1.03
BouncycastleBc-java Version1.04
BouncycastleBc-java Version1.05
BouncycastleBc-java Version1.06
BouncycastleBc-java Version1.07
BouncycastleBc-java Version1.08
BouncycastleBc-java Version1.09
BouncycastleBc-java Version1.10
BouncycastleBc-java Version1.11
BouncycastleBc-java Version1.12
BouncycastleBc-java Version1.13
BouncycastleBc-java Version1.14
BouncycastleBc-java Version1.15
BouncycastleBc-java Version1.16
BouncycastleBc-java Version1.17
BouncycastleBc-java Version1.18
BouncycastleBc-java Version1.19
BouncycastleBc-java Version1.20
BouncycastleBc-java Version1.21
BouncycastleBc-java Version1.22
BouncycastleBc-java Version1.23
BouncycastleBc-java Version1.24
BouncycastleBc-java Version1.25
BouncycastleBc-java Version1.26
BouncycastleBc-java Version1.27
BouncycastleBc-java Version1.28
BouncycastleBc-java Version1.29
BouncycastleBc-java Version1.30
BouncycastleBc-java Version1.31
BouncycastleBc-java Version1.32
BouncycastleBc-java Version1.33
BouncycastleBc-java Version1.34
BouncycastleBc-java Version1.35
BouncycastleBc-java Version1.36
BouncycastleBc-java Version1.37
BouncycastleBc-java Version1.38
BouncycastleBc-java Version1.39
BouncycastleBc-java Version1.40
BouncycastleBc-java Version1.41
BouncycastleBc-java Version1.42
BouncycastleBc-java Version1.43
BouncycastleBc-java Version1.44
BouncycastleBc-java Version1.45
BouncycastleBc-java Version1.46
BouncycastleBc-java Version1.47
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.53% 0.647
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 4.9 4.9
AV:N/AC:H/Au:N/C:P/I:P/A:N